First published: Fri May 06 2022(Updated: )
An issue was discovered in the Sametime chat feature in the Notes 11.0 - 11.0.1 FP4 clients. An authenticated Sametime chat user could cause Remote Code Execution on another chat client by sending a specially formatted message through chat containing Javascript code.
Credit: psirt@hcl.com
Affected Software | Affected Version | How to fix |
---|---|---|
Hcltech Hcl Inotes | =11.0.0 | |
Hcltech Hcl Inotes | =11.0.1 | |
Hcltech Hcl Inotes | =11.0.1-fixpack1 | |
Hcltech Hcl Inotes | =11.0.1-fixpack2 | |
Hcltech Hcl Inotes | =11.0.1-fixpack3 | |
Hcltech Hcl Inotes | =11.0.1-fixpack4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-27760 is a vulnerability in the Sametime chat feature in the Notes 11.0 - 11.0.1 FP4 clients that allows an authenticated user to execute remote code on another chat client.
CVE-2021-27760 has a severity rating of 5.5 (medium).
CVE-2021-27760 affects the following versions of Hcltech Hcl Inotes: 11.0.0, 11.0.1, 11.0.1-fixpack1, 11.0.1-fixpack2, 11.0.1-fixpack3, and 11.0.1-fixpack4.
To fix CVE-2021-27760, update your Hcltech Hcl Inotes software to version 11.0.1-fixpack4 or apply the necessary patches provided by HCL Technologies.
You can find more information about CVE-2021-27760 at https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0097670.