First published: Sat Nov 21 2020(Updated: )
HCL Domino is susceptible to a Denial of Service vulnerability caused by improper validation of user-supplied input. A remote unauthenticated attacker could exploit this vulnerability using a specially-crafted email message to hang the server. Versions previous to releases 9.0.1 FP10 IF6, 10.0.1 FP5 and 11.0.1 are affected.
Credit: psirt@hcl.com
Affected Software | Affected Version | How to fix |
---|---|---|
HCL Domino | <9.0.1 | |
HCL Domino | >=10.0.0<10.0.1 | |
HCL Domino | >=11.0.0<11.0.1 | |
HCL Domino | =9.0.1 | |
HCL Domino | =9.0.1-feature_pack_10_interim_fix_3 | |
HCL Domino | =9.0.1-feature_pack_10_interim_fix_4 | |
HCL Domino | =9.0.1-feature_pack_8 | |
HCL Domino | =9.0.1-feature_pack_8_interim_fix_1 | |
HCL Domino | =9.0.1-feature_pack_8_interim_fix_2 | |
HCL Domino | =9.0.1-feature_pack_8_interim_fix_3 | |
HCL Domino | =10.0.1 | |
HCL Domino | =10.0.1-fix_pack_1 | |
HCL Domino | =10.0.1-fix_pack_2 | |
HCL Domino | =10.0.1-fix_pack_3 | |
HCL Domino | =10.0.1-fix_pack_4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-14230 is classified as high due to its potential to cause Denial of Service.
To fix CVE-2020-14230, updates should be applied to HCL Domino versions 9.0.1 FP10 IF6 or later and 10.0.1 FP5 or later.
CVE-2020-14230 affects HCL Domino versions prior to 9.0.1 FP10 IF6 and 10.0.1 FP5.
The impact of CVE-2020-14230 allows a remote unauthenticated attacker to hang the server by sending a specially-crafted email.
Yes, CVE-2020-14230 can be exploited remotely by an unauthenticated attacker.