Show filters
218 Total Results
Displaying 201-210 of 218
Sort by:
Attacker Value
Unknown

CVE-2017-1712

Disclosure Date: July 01, 2020 (last updated February 21, 2025)
"A vulnerability in the TLS protocol implementation of the Domino server could allow an unauthenticated, remote attacker to access sensitive information, aka a Return of Bleichenbacher's Oracle Threat (ROBOT) attack. An attacker could iteratively query a server running a vulnerable TLS stack implementation to perform cryptanalytic operations that may allow decryption of previously captured TLS sessions."
Attacker Value
Unknown

CVE-2020-4089

Disclosure Date: June 26, 2020 (last updated November 28, 2024)
HCL Notes is vulnerable to an information leakage vulnerability through its support for the 'mailto' protocol. This vulnerability could result in files from the user's filesystem or connected network filesystems being leaked to a third party. All versions of HCL Notes 9, 10 and 11 are affected.
Attacker Value
Unknown

CVE-2020-4101

Disclosure Date: June 11, 2020 (last updated February 21, 2025)
"HCL Digital Experience is susceptible to Server Side Request Forgery."
Attacker Value
Unknown

CVE-2020-4092

Disclosure Date: May 06, 2020 (last updated February 21, 2025)
"If port encryption is not enabled on the Domino Server, HCL Nomad on Android and iOS Platforms will communicate in clear text and does not currently have a user interface option to change the setting to request an encrypted communication channel with the Domino server. This can potentially expose sensitive information including but not limited to server names, user IDs and document content."
Attacker Value
Unknown

CVE-2019-4209

Disclosure Date: May 01, 2020 (last updated February 21, 2025)
HCL Connections v5.5, v6.0, and v6.5 contains an open redirect vulnerability which could be exploited by an attacker to conduct phishing attacks.
Attacker Value
Unknown

CVE-2020-4085

Disclosure Date: April 22, 2020 (last updated February 21, 2025)
"HCL Connections is vulnerable to possible information leakage and could disclose sensitive information via stack trace to a local user."
Attacker Value
Unknown

CVE-2019-4327

Disclosure Date: April 21, 2020 (last updated February 21, 2025)
"HCL AppScan Enterprise uses hard-coded credentials which can be exploited by attackers to get unauthorized access to application's encrypted files."
Attacker Value
Unknown

CVE-2019-4391

Disclosure Date: April 07, 2020 (last updated February 21, 2025)
HCL AppScan Standard is vulnerable to XML External Entity Injection (XXE) attack when processing XML data
Attacker Value
Unknown

CVE-2019-4393

Disclosure Date: April 07, 2020 (last updated February 21, 2025)
HCL AppScan Standard is vulnerable to excessive authorization attempts
Attacker Value
Unknown

CVE-2020-4084

Disclosure Date: March 09, 2020 (last updated February 21, 2025)
HCL Connections v5.5, v6.0, and v6.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.