First published: Sat Dec 17 2022(Updated: )
HCL Domino is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted Lotus Ami Pro file. This is different from the vulnerability described in CVE-2022-44750. This vulnerability applies to software previously licensed by IBM.
Credit: psirt@hcl.com
Affected Software | Affected Version | How to fix |
---|---|---|
Hcltech Domino | =9.0 | |
Hcltech Domino | =9.0.1 | |
Hcltech Domino | =9.0.1 | |
Hcltech Domino | =9.0.1-feature_pack_10_interim_fix_3 | |
Hcltech Domino | =9.0.1-feature_pack_10_interim_fix_4 | |
Hcltech Domino | =9.0.1-feature_pack_10_interim_fix_5 | |
Hcltech Domino | =9.0.1-feature_pack_8 | |
Hcltech Domino | =9.0.1-feature_pack_8_interim_fix_1 | |
Hcltech Domino | =9.0.1-feature_pack_8_interim_fix_2 | |
Hcltech Domino | =9.0.1-feature_pack_8_interim_fix_3 | |
Hcltech Domino | =9.0.1-fixpack_10 | |
Hcltech Domino | =9.0.1-fixpack_3 | |
Hcltech Domino | =9.0.1-fixpack_4 | |
Hcltech Domino | =9.0.1-fixpack_5 | |
Hcltech Domino | =9.0.1-fixpack_6 | |
Hcltech Domino | =9.0.1-fixpack_7 | |
Hcltech Domino | =9.0.1-fixpack_8 | |
Hcltech Domino | =9.0.1-fixpack_9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-44754 is critical with a CVSS score of 7.8.
The affected software for CVE-2022-44754 is HCL Domino versions 9.0 and 9.0.1.
A remote unauthenticated attacker can exploit CVE-2022-44754 by sending crafted Lotus Ami Pro files to the vulnerable HCL Domino application.
Yes, a fix is available for CVE-2022-44754. Please refer to the vendor's support website for more information.
The Common Weakness Enumerations (CWEs) associated with CVE-2022-44754 are CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer) and CWE-787 (Out-of-bounds Write).