Improper Request Handling in HCL Domino
CVE-2021-27759

2.3LOW

Key Information:

Vendor
CVE Published:
6 May 2022

Summary

This vulnerability in HCL Domino occurs due to insufficient verification of user requests, which might allow an attacker to manipulate a victim's browser into sending unintended HTTP requests to an arbitrary URL. This could lead to unauthorized actions being executed without the user's consent, compromising sensitive information and the integrity of the application.

Affected Version(s)

HCL BigFix Inventory 9.x

HCL BigFix Inventory 10.x

References

CVSS V3.1

Score:
2.3
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.