CVE-2022-44754: HCL Domino is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView.
HCL Domino is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted Lotus Ami Pro file. This is different from the vulnerability described in CVE-2022-44750. This vulnerability applies to software previously licensed by IBM.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-44754?
The severity of CVE-2022-44754 is critical with a CVSS score of 7.8.
What is the affected software for CVE-2022-44754?
The affected software for CVE-2022-44754 is HCL Domino versions 9.0 and 9.0.1.
How can a remote unauthenticated attacker exploit CVE-2022-44754?
A remote unauthenticated attacker can exploit CVE-2022-44754 by sending crafted Lotus Ami Pro files to the vulnerable HCL Domino application.
Is there a fix available for CVE-2022-44754?
Yes, a fix is available for CVE-2022-44754. Please refer to the vendor's support website for more information.
What are the Common Weakness Enumerations (CWEs) associated with CVE-2022-44754?
The Common Weakness Enumerations (CWEs) associated with CVE-2022-44754 are CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer) and CWE-787 (Out-of-bounds Write).