CVE-2021-27760: HCL Notes 11.0 - 11.0.1 FP4 Sametime Embedded chat clients are vulnerable to group chats loading script on restart
An issue was discovered in the Sametime chat feature in the Notes 11.0 - 11.0.1 FP4 clients. An authenticated Sametime chat user could cause Remote Code Execution on another chat client by sending a specially formatted message through chat containing Javascript code.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-27760?
CVE-2021-27760 is a vulnerability in the Sametime chat feature in the Notes 11.0 - 11.0.1 FP4 clients that allows an authenticated user to execute remote code on another chat client.
How severe is CVE-2021-27760?
CVE-2021-27760 has a severity rating of 5.5 (medium).
Which software versions are affected by CVE-2021-27760?
CVE-2021-27760 affects the following versions of Hcltech Hcl Inotes: 11.0.0, 11.0.1, 11.0.1-fixpack1, 11.0.1-fixpack2, 11.0.1-fixpack3, and 11.0.1-fixpack4.
How can I fix CVE-2021-27760?
To fix CVE-2021-27760, update your Hcltech Hcl Inotes software to version 11.0.1-fixpack4 or apply the necessary patches provided by HCL Technologies.
Where can I find more information about CVE-2021-27760?
You can find more information about CVE-2021-27760 at https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0097670.