CVE-2022-27558

MEDIUM

HCL iNotes - Info Disclosure

Title source: llm
STIX 2.1

Description

HCL iNotes is susceptible to a Broken Password Strength Checks vulnerability. Custom password policies are not enforced on certain iNotes forms which could allow users to set weak passwords, leading to easier cracking.

Scores

CVSS v3 5.9
EPSS 0.0022
EPSS Percentile 44.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-521
Status published
Products (2)
hcltech/domino 12.0.1 (2 CPE variants)
hcltech/hcl_inotes 12.0.1 (2 CPE variants)
Published Aug 29, 2022
Tracked Since Feb 18, 2026