LDAP Service Lockout Policy Bypass in HCL Domino
CVE-2020-4129

5.3MEDIUM

Key Information:

Vendor
CVE Published:
1 December 2020

Summary

HCL Domino is affected by a vulnerability in its LDAP service that allows an unauthenticated attacker to bypass lockout policies. This could enable attackers to conduct brute force attacks on the LDAP service, potentially compromising the security of sensitive data. To mitigate this risk, users are advised to upgrade to the patched versions of HCL Domino.

Affected Version(s)

HCL Domino v9.0.1 FP10 IF6, v10.0.1 FP6, v11.0.1 FP1

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.