First published: Thu Nov 05 2020(Updated: )
In HCL Notes version 9 previous to release 9.0.1 FixPack 10 Interim Fix 8, version 10 previous to release 10.0.1 FixPack 6 and version 11 previous to 11.0.1 FixPack 1, a vulnerability in the input parameter handling of the Notes Client could potentially be exploited by an attacker resulting in a buffer overflow. This could enable an attacker to crash HCL Notes or execute attacker-controlled code on the client.
Credit: psirt@hcl.com
Affected Software | Affected Version | How to fix |
---|---|---|
Hcltech Notes | >=9.0<=9.0.1 | |
Hcltech Notes | >=11.0<=11.0.1 | |
Hcltech Notes | =9.0.1-fp10 | |
Hcltech Notes | =9.0.1-fp10if1 | |
Hcltech Notes | =9.0.1-fp10if2 | |
Hcltech Notes | =9.0.1-fp10if3 | |
Hcltech Notes | =9.0.1-fp10if4 | |
Hcltech Notes | =9.0.1-fp10if5 | |
Hcltech Notes | =9.0.1-fp10if6 | |
Hcltech Notes | =9.0.1-fp10if7 | |
Hcltech Notes | =9.0.1-fp1if1 | |
Hcltech Notes | =9.0.1-fp1if2 | |
Hcltech Notes | =9.0.1-fp2if1 | |
Hcltech Notes | =9.0.1-fp2if2 | |
Hcltech Notes | =9.0.1-fp2if3 | |
Hcltech Notes | =9.0.1-fp2if4 | |
Hcltech Notes | =9.0.1-fp3if1 | |
Hcltech Notes | =9.0.1-fp3if2 | |
Hcltech Notes | =9.0.1-fp3if3 | |
Hcltech Notes | =9.0.1-fp3if4 | |
Hcltech Notes | =9.0.1-fp4if1 | |
Hcltech Notes | =9.0.1-fp4if2 | |
Hcltech Notes | =9.0.1-fp5if1 | |
Hcltech Notes | =9.0.1-fp5if2 | |
Hcltech Notes | =9.0.1-fp5if3 | |
Hcltech Notes | =9.0.1-fp7if1 | |
Hcltech Notes | =9.0.1-fp7if2 | |
Hcltech Notes | =9.0.1-fp8if1 | |
Hcltech Notes | =9.0.1-fp9if1 | |
Hcltech Notes | =9.0.1-fp9if2 | |
Hcltech Notes | =10.0.0-fp1 | |
Hcltech Notes | =10.0.0-fp2 | |
Hcltech Notes | =10.0.0-fp3 | |
Hcltech Notes | =10.0.0-fp4 | |
Hcltech Notes | =10.0.0-fp5 | |
Hcltech Notes | =10.0.1-fp1 | |
Hcltech Notes | =10.0.1-fp2 | |
Hcltech Notes | =10.0.1-fp3 | |
Hcltech Notes | =10.0.1-fp4 | |
Hcltech Notes | =10.0.1-fp5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-4097 is a vulnerability in the input parameter handling of HCL Notes Client that could be exploited by an attacker resulting in a buffer overflow.
HCL Notes versions 9.0 and previous, version 10.0 and previous, and version 11.0 and previous are affected.
CVE-2020-4097 has a severity rating of 6.8, indicating a medium severity.
To fix CVE-2020-4097, update HCL Notes to version 9.0.1 FixPack 10 Interim Fix 8 or later, version 10.0.1 FixPack 6 or later, or version 11.0.1 FixPack 1 or later.
More information about CVE-2020-4097 can be found at: [https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0084796](https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0084796)