// For flags

CVE-2020-4126

 

Severity Score

5.9
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

HCL iNotes is susceptible to a sensitive cookie exposure vulnerability. This can allow an unauthenticated remote attacker to capture the cookie by intercepting its transmission within an http session. Fixes are available in HCL Domino and iNotes versions 10.0.1 FP6 and 11.0.1 FP2 and later.

HCL iNotes es susceptible a una vulnerabilidad de exposición de cookies confidenciales. Esto puede permitir a un atacante remoto no autenticado capturar la cookie interceptando su transmisión dentro de una sesión http. Las correcciones están disponibles en HCL Domino e iNotes versiones 10.0.1 FP6 y 11.0.1 FP2 y posteriores

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
Partial
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2019-12-30 CVE Reserved
  • 2020-11-30 CVE Published
  • 2024-08-04 CVE Updated
  • 2024-08-17 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-311: Missing Encryption of Sensitive Data
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Hcltech
Search vendor "Hcltech"
Hcl Inotes
Search vendor "Hcltech" for product "Hcl Inotes"
>= 9.0 < 10.0.1
Search vendor "Hcltech" for product "Hcl Inotes" and version " >= 9.0 < 10.0.1"
-
Affected
Hcltech
Search vendor "Hcltech"
Hcl Inotes
Search vendor "Hcltech" for product "Hcl Inotes"
>= 11.0.0 < 11.0.1
Search vendor "Hcltech" for product "Hcl Inotes" and version " >= 11.0.0 < 11.0.1"
-
Affected
Hcltech
Search vendor "Hcltech"
Hcl Inotes
Search vendor "Hcltech" for product "Hcl Inotes"
10.0.1
Search vendor "Hcltech" for product "Hcl Inotes" and version "10.0.1"
-
Affected
Hcltech
Search vendor "Hcltech"
Hcl Inotes
Search vendor "Hcltech" for product "Hcl Inotes"
10.0.1
Search vendor "Hcltech" for product "Hcl Inotes" and version "10.0.1"
fixpack1
Affected
Hcltech
Search vendor "Hcltech"
Hcl Inotes
Search vendor "Hcltech" for product "Hcl Inotes"
10.0.1
Search vendor "Hcltech" for product "Hcl Inotes" and version "10.0.1"
fixpack2
Affected
Hcltech
Search vendor "Hcltech"
Hcl Inotes
Search vendor "Hcltech" for product "Hcl Inotes"
10.0.1
Search vendor "Hcltech" for product "Hcl Inotes" and version "10.0.1"
fixpack3
Affected
Hcltech
Search vendor "Hcltech"
Hcl Inotes
Search vendor "Hcltech" for product "Hcl Inotes"
10.0.1
Search vendor "Hcltech" for product "Hcl Inotes" and version "10.0.1"
fixpack4
Affected
Hcltech
Search vendor "Hcltech"
Hcl Inotes
Search vendor "Hcltech" for product "Hcl Inotes"
10.0.1
Search vendor "Hcltech" for product "Hcl Inotes" and version "10.0.1"
fixpack5
Affected
Hcltech
Search vendor "Hcltech"
Hcl Inotes
Search vendor "Hcltech" for product "Hcl Inotes"
11.0.1
Search vendor "Hcltech" for product "Hcl Inotes" and version "11.0.1"
-
Affected
Hcltech
Search vendor "Hcltech"
Hcl Inotes
Search vendor "Hcltech" for product "Hcl Inotes"
11.0.1
Search vendor "Hcltech" for product "Hcl Inotes" and version "11.0.1"
fixpack1
Affected