CVE-2020-4128: Medium severity ibm domino vulnerability
Published Dec 1, 2020
·Updated
HCL Domino is susceptible to a lockout policy bypass vulnerability in the ID Vault service. An unauthenticated attacker could use this vulnerability to mount a brute force attack against the ID Vault service.
Affected Software
8 affected components
hcltech Domino>=9.0.0<=9.0.1
hcltech Domino>=10.0.0<=10.0.1
hcltech Domino>=11.0.0<=11.0.1
hcltech Domino=10.0.1
hcltech Domino=10.0.1-fix_pack_1
hcltech Domino=10.0.1-fix_pack_2
hcltech Domino=10.0.1-fix_pack_3
hcltech Domino=10.0.1-fix_pack_4
Remediation
Event History
Dec 1, 2020
CVE Published
via MITRE·01:12 PM
Data Sourced
via MITRE·01:12 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2020-4128?
CVE-2020-4128 is a vulnerability in HCL Domino that allows an unauthenticated attacker to bypass the lockout policy in the ID Vault service.
2
What is the severity of CVE-2020-4128?
The severity of CVE-2020-4128 is medium with a CVSS score of 5.3.
3
Which versions of HCL Domino are affected?
HCL Domino versions 9.0.0 to 9.0.1, 10.0.0 to 10.0.1, and 11.0.0 to 11.0.1 are affected.
4
How can an attacker exploit CVE-2020-4128?
An attacker can exploit CVE-2020-4128 by conducting a brute force attack against the ID Vault service.
5
Is there a fix available for CVE-2020-4128?
Yes, HCL Domino versions 10.0.1 Fix Pack 5 and 11.0.1 Fix Pack 3 or later include a fix for CVE-2020-4128.