CVE-2022-38654

HCL Domino is susceptible to an information disclosure vulnerability.  In some scenarios, local calls made on the server to search the Domino directory will ignore xACL read restrictions.  An authenticated attacker could leverage this vulnerability to access attributes from a user's person record.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.5 MEDIUM
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
HCLCNA
5.5 MEDIUM
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 19%
VendorProductVersion
hcltechdomino
9.0.1
hcltechdomino
9.0.1:feature_pack_10_interim_fix_3
hcltechdomino
9.0.1:feature_pack_10_interim_fix_4
hcltechdomino
9.0.1:feature_pack_10_interim_fix_5
hcltechdomino
9.0.1:feature_pack_8
hcltechdomino
9.0.1:feature_pack_8_interim_fix_1
hcltechdomino
9.0.1:feature_pack_8_interim_fix_2
hcltechdomino
9.0.1:feature_pack_8_interim_fix_3
hcltechdomino
9.0.1:fixpack_3
hcltechdomino
9.0.1:fixpack_4
hcltechdomino
9.0.1:fixpack_5
hcltechdomino
9.0.1:fixpack_6
hcltechdomino
9.0.1:fixpack_7
hcltechdomino
9.0.1:fixpack_8
hcltechdomino
9.0.1:fixpack_9
hcltechdomino
10.0.0
hcltechdomino
10.0.1
hcltechdomino
10.0.1:fixpack_1
hcltechdomino
10.0.1:fixpack_2
hcltechdomino
10.0.1:fixpack_3
hcltechdomino
10.0.1:fixpack_4
hcltechdomino
10.0.1:fixpack_5
hcltechdomino
10.0.1:fixpack_6
hcltechdomino
10.0.1:fixpack_7
hcltechdomino
11.0.1
hcltechdomino
11.0.1:fixpack_1
hcltechdomino
11.0.1:fixpack_2
hcltechdomino
11.0.1:fixpack_3
hcltechdomino
11.0.1:fixpack_4
hcltechdomino
11.0.1:fixpack_5
hcltechdomino
12.0
𝑥
= Vulnerable software versions