Login CSRF Vulnerability in HCL Domino
CVE-2020-4127
What is CVE-2020-4127?
HCL Domino is impacted by a Login Cross-Site Request Forgery (CSRF) vulnerability that allows an attacker to exploit a user's session with valid credentials. By manipulating user interactions, an attacker can trick a user into accessing systems under a different identity. This vulnerability not only compromises individual user accounts but may also provide unauthorized access to internal systems from external networks. Users are strongly encouraged to upgrade to the latest versions of HCL Domino to mitigate this risk. Relevant patches have been released in versions 9.0.1 FP10 IF6, 10.0.1 FP6, and 11.0.1 FP1 and later.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
HCL Domino v9.0.1 FP10 IF6, v10.0.1 FP6, v11.0.1 FP1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved