Description
HCL iNotes is susceptible to a sensitive cookie exposure vulnerability. This can allow an unauthenticated remote attacker to capture the cookie by intercepting its transmission within an http session. Fixes are available in HCL Domino and iNotes versions 10.0.1 FP6 and 11.0.1 FP2 and later.
Scores
CVSS v3
5.9
EPSS
0.0019
EPSS Percentile
39.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Details
CWE
CWE-311
Status
published
Products (3)
hcltech/hcl_inotes
10.0.1 (6 CPE variants)
hcltech/hcl_inotes
11.0.1 (2 CPE variants)
hcltech/hcl_inotes
9.0 - 10.0.1
Published
Dec 01, 2020
Tracked Since
Feb 18, 2026