First published: Wed Aug 24 2022(Updated: )
HCL iNotes is susceptible to a Broken Password Strength Checks vulnerability. Custom password policies are not enforced on certain iNotes forms which could allow users to set weak passwords, leading to easier cracking.
Credit: psirt@hcl.com
Affected Software | Affected Version | How to fix |
---|---|---|
Hcltech Domino | =12.0.1 | |
Hcltech Domino | =12.0.1-fixpack_1 | |
Hcltech Hcl Inotes | =12.0.1 | |
Hcltech Hcl Inotes | =12.0.1-fixpack_1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2022-27558.
The title of this vulnerability is HCL iNotes Broken Password Strength Checks vulnerability.
The severity of CVE-2022-27558 is high with a CVSS score of 7.5.
Hcltech Domino versions 12.0.1 and 12.0.1-fixpack_1, as well as Hcltech Hcl Inotes versions 12.0.1 and 12.0.1-fixpack_1 are affected by CVE-2022-27558.
To fix this vulnerability, it is recommended to apply the appropriate fix pack or version upgrade provided by HCLTech.