CVE-2022-27547: HCL iNotes is susceptible to a link to non-existent domain vulnerability.
HCL iNotes is susceptible to a link to non-existent domain vulnerability. An attacker could use this vulnerability to trick a user into supplying sensitive information such as username, password, credit card number, etc.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-27547?
CVE-2022-27547 is rated as a high severity vulnerability due to its potential to expose sensitive user information.
How do I fix CVE-2022-27547?
To fix CVE-2022-27547, ensure you apply the latest security updates from HCL for affected iNotes versions.
Which versions of HCL iNotes are affected by CVE-2022-27547?
CVE-2022-27547 affects HCL iNotes versions 9.0.1 through 12.0.1 and their respective fix packs.
What kind of attack can exploit CVE-2022-27547?
CVE-2022-27547 can be exploited through phishing attacks that lead users to non-existent domains, tricking them into providing sensitive information.
Is there a workaround for CVE-2022-27547?
Currently, there is no specific workaround for CVE-2022-27547, and upgrading to the patched versions is recommended for protection.