Content-Security-Policy Misconfiguration in HCL Domino's Nomad Server
CVE-2025-62328

3.7LOW

Key Information:

Vendor
CVE Published:
11 March 2026

What is CVE-2025-62328?

The HCL Nomad Server on Domino is vulnerable due to a default misconfiguration of the Content-Security-Policy header, specifically the absence of the frame-ancestors directive. This oversight can potentially expose sensitive information to attackers through various unspecified vectors, necessitating immediate attention to mitigate risks.

Affected Version(s)

Nomad server on Domino <1.0.19

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.