Lockout Policy Bypass Vulnerability in HCL Domino ID Vault Service
CVE-2020-4128
5.3MEDIUM
Summary
HCL Domino is exposed to a lockout policy bypass vulnerability that affects its ID Vault service. This flaw allows unauthenticated attackers to circumvent the security controls intended to protect user accounts, potentially enabling them to execute brute force attacks. When exploited, this vulnerability can compromise the integrity of the ID Vault, leading to unauthorized access and data breaches. Organizations using this service should be vigilant and implement appropriate security measures to mitigate the risk.
Affected Version(s)
HCL Domino v9
HCL Domino v10
HCL Domino v11
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved