First published: Fri Nov 04 2022(Updated: )
HCL XPages applications are susceptible to a Cross Site Request Forgery (CSRF) vulnerability. An unauthenticated attacker could exploit this vulnerability to perform actions in the application on behalf of the logged in user.
Credit: psirt@hcl.com
Affected Software | Affected Version | How to fix |
---|---|---|
Hcltech Domino | <9.0.1 | |
Hcltech Domino | =9.0.1-feature_pack_10_interim_fix_3 | |
Hcltech Domino | =9.0.1-feature_pack_10_interim_fix_4 | |
Hcltech Domino | =9.0.1-feature_pack_10_interim_fix_5 | |
Hcltech Domino | =9.0.1-feature_pack_8 | |
Hcltech Domino | =9.0.1-feature_pack_8_interim_fix_1 | |
Hcltech Domino | =9.0.1-feature_pack_8_interim_fix_2 | |
Hcltech Domino | =9.0.1-feature_pack_8_interim_fix_3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-38660 is a Cross Site Request Forgery (CSRF) vulnerability in HCL XPages applications.
CVE-2022-38660 allows an unauthenticated attacker to perform actions in the application on behalf of the logged-in user.
CVE-2022-38660 has a severity rating of 8.8 (High).
The following versions of HCL Domino are affected by CVE-2022-38660: 9.0.1, 9.0.1-feature_pack_10_interim_fix_3, 9.0.1-feature_pack_10_interim_fix_4, 9.0.1-feature_pack_10_interim_fix_5, 9.0.1-feature_pack_8, 9.0.1-feature_pack_8_interim_fix_1, 9.0.1-feature_pack_8_interim_fix_2, 9.0.1-feature_pack_8_interim_fix_3.
To mitigate CVE-2022-38660, it is recommended to apply the necessary security patches or updates provided by HCL.