HCL XPages applications are susceptible to a Cross Site Request Forgery (CSRF) vulnerability. An unauthenticated attacker could exploit this vulnerability to perform actions in the application on behalf of the logged in user.
References
Link | Resource |
---|---|
https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0101037 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
07 Nov 2022, 17:18
Type | Values Removed | Values Added |
---|---|---|
References | (MISC) https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0101037 - Vendor Advisory | |
CPE | cpe:2.3:a:hcltech:domino:*:*:*:*:*:*:*:* cpe:2.3:a:hcltech:domino:9.0.1:feature_pack_10_interim_fix_4:*:*:*:*:*:* cpe:2.3:a:hcltech:domino:9.0.1:feature_pack_8:*:*:*:*:*:* cpe:2.3:a:hcltech:domino:9.0.1:feature_pack_10_interim_fix_3:*:*:*:*:*:* cpe:2.3:a:hcltech:domino:9.0.1:feature_pack_8_interim_fix_3:*:*:*:*:*:* cpe:2.3:a:hcltech:domino:9.0.1:feature_pack_8_interim_fix_1:*:*:*:*:*:* cpe:2.3:a:hcltech:domino:9.0.1:feature_pack_8_interim_fix_2:*:*:*:*:*:* cpe:2.3:a:hcltech:domino:9.0.1:feature_pack_10_interim_fix_5:*:*:*:*:*:* |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.8 |
CWE | CWE-352 |
04 Nov 2022, 20:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2022-11-04 20:15
Updated : 2024-02-04 22:51
NVD link : CVE-2022-38660
Mitre link : CVE-2022-38660
CVE.ORG link : CVE-2022-38660
JSON object : View
Products Affected
hcltech
- domino
CWE
CWE-352
Cross-Site Request Forgery (CSRF)