CVE-2022-27558: HCL iNotes is susceptible to a Broken Password Strength Checks vulnerability.
Published Aug 29, 2022
·Updated
HCL iNotes is susceptible to a Broken Password Strength Checks vulnerability. Custom password policies are not enforced on certain iNotes forms which could allow users to set weak passwords, leading to easier cracking.
Affected Software
4 affected components
hcltech Domino=12.0.1
hcltech Domino=12.0.1-fixpack_1
hcltech Hcl Inotes=12.0.1
hcltech Hcl Inotes=12.0.1-fixpack_1
Event History
Aug 29, 2022
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2022-27558.
2
What is the title of this vulnerability?
The title of this vulnerability is HCL iNotes Broken Password Strength Checks vulnerability.
3
What is the severity of CVE-2022-27558?
The severity of CVE-2022-27558 is high with a CVSS score of 7.5.
4
Which software versions are affected by CVE-2022-27558?
Hcltech Domino versions 12.0.1 and 12.0.1-fixpack_1, as well as Hcltech Hcl Inotes versions 12.0.1 and 12.0.1-fixpack_1 are affected by CVE-2022-27558.
5
How can this vulnerability be fixed?
To fix this vulnerability, it is recommended to apply the appropriate fix pack or version upgrade provided by HCLTech.