First published: Tue Dec 01 2020(Updated: )
HCL Domino is susceptible to a lockout policy bypass vulnerability in the ID Vault service. An unauthenticated attacker could use this vulnerability to mount a brute force attack against the ID Vault service.
Credit: psirt@hcl.com
Affected Software | Affected Version | How to fix |
---|---|---|
Hcltech Domino | >=9.0.0<=9.0.1 | |
Hcltech Domino | >=10.0.0<=10.0.1 | |
Hcltech Domino | >=11.0.0<=11.0.1 | |
Hcltech Domino | =10.0.1 | |
Hcltech Domino | =10.0.1-fix_pack_1 | |
Hcltech Domino | =10.0.1-fix_pack_2 | |
Hcltech Domino | =10.0.1-fix_pack_3 | |
Hcltech Domino | =10.0.1-fix_pack_4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-4128 is a vulnerability in HCL Domino that allows an unauthenticated attacker to bypass the lockout policy in the ID Vault service.
The severity of CVE-2020-4128 is medium with a CVSS score of 5.3.
HCL Domino versions 9.0.0 to 9.0.1, 10.0.0 to 10.0.1, and 11.0.0 to 11.0.1 are affected.
An attacker can exploit CVE-2020-4128 by conducting a brute force attack against the ID Vault service.
Yes, HCL Domino versions 10.0.1 Fix Pack 5 and 11.0.1 Fix Pack 3 or later include a fix for CVE-2020-4128.