Lockout Policy Bypass Vulnerability in HCL Domino ID Vault Service
CVE-2020-4128

5.3MEDIUM

Key Information:

Vendor
CVE Published:
1 December 2020

Summary

HCL Domino is exposed to a lockout policy bypass vulnerability that affects its ID Vault service. This flaw allows unauthenticated attackers to circumvent the security controls intended to protect user accounts, potentially enabling them to execute brute force attacks. When exploited, this vulnerability can compromise the integrity of the ID Vault, leading to unauthorized access and data breaches. Organizations using this service should be vigilant and implement appropriate security measures to mitigate the risk.

Affected Version(s)

HCL Domino v9

HCL Domino v10

HCL Domino v11

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.