CVE-2020-4127: CSRF
HCL Domino is susceptible to a Login CSRF vulnerability. With a valid credential, an attacker could trick a user into accessing a system under another ID or use an intranet user's system to access internal systems from the internet. Fixes are available in HCL Domino versions 9.0.1 FP10 IF6, 10.0.1 FP6 and 11.0.1 FP1 and later.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-4127?
The severity of CVE-2020-4127 is considered to be medium, indicating a significant risk of exploitation.
How do I fix CVE-2020-4127?
To fix CVE-2020-4127, upgrade to HCL Domino versions 9.0.1 FP10 IF6, 10.0.1 FP1, or later versions available.
What systems are affected by CVE-2020-4127?
CVE-2020-4127 affects HCL Domino versions 9.0.1, 10.0.1, and 11.0.1 prior to the application of the necessary updates.
Can CVE-2020-4127 lead to unauthorized access?
Yes, CVE-2020-4127 can allow an attacker to gain unauthorized access to internal systems if exploitation occurs.
Is there a known exploit for CVE-2020-4127?
As of now, there are no publicly disclosed known exploits for CVE-2020-4127, but it remains a potential vulnerability.