CVE-2024-30146

Improper access control of endpoint in HCL Domino Leap
allows certain admin users to import applications from the
server's filesystem.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.1 MEDIUM
NETWORK
HIGH
HIGH
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L
HCLCNA
4.1 MEDIUM
NETWORK
HIGH
HIGH
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 6%
VendorProductVersion
hcltechdomino_leap
1.1.3 ≤
𝑥
< 1.1.5
𝑥
= Vulnerable software versions