CVE-2022-38660: HCL XPages applications are susceptible to Cross Site Request Forgery (CSRF) vulnerability
HCL XPages applications are susceptible to a Cross Site Request Forgery (CSRF) vulnerability. An unauthenticated attacker could exploit this vulnerability to perform actions in the application on behalf of the logged in user.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-38660?
CVE-2022-38660 is a Cross Site Request Forgery (CSRF) vulnerability in HCL XPages applications.
How does CVE-2022-38660 affect HCL XPages applications?
CVE-2022-38660 allows an unauthenticated attacker to perform actions in the application on behalf of the logged-in user.
What is the severity of CVE-2022-38660?
CVE-2022-38660 has a severity rating of 8.8 (High).
Which versions of HCL Domino are affected by CVE-2022-38660?
The following versions of HCL Domino are affected by CVE-2022-38660: 9.0.1, 9.0.1-feature_pack_10_interim_fix_3, 9.0.1-feature_pack_10_interim_fix_4, 9.0.1-feature_pack_10_interim_fix_5, 9.0.1-feature_pack_8, 9.0.1-feature_pack_8_interim_fix_1, 9.0.1-feature_pack_8_interim_fix_2, 9.0.1-feature_pack_8_interim_fix_3.
How can the vulnerability CVE-2022-38660 be mitigated?
To mitigate CVE-2022-38660, it is recommended to apply the necessary security patches or updates provided by HCL.