ID

VAR-202105-1519


CVE

CVE-2020-4107


TITLE

HCL Technologies Limited  of  Domino server  Vulnerability in

Trust: 0.8

sources: JVNDB: JVNDB-2022-010217

DESCRIPTION

HCL Domino is affected by an Insufficient Access Control vulnerability. An authenticated attacker with local access to the system could exploit this vulnerability to attain escalation of privileges, denial of service, or information disclosure. HCL Technologies Limited of Domino server Exists in unspecified vulnerabilities.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state

Trust: 1.71

sources: NVD: CVE-2020-4107 // JVNDB: JVNDB-2022-010217 // VULMON: CVE-2020-4107

AFFECTED PRODUCTS

vendor:hcltechmodel:dominoscope:eqversion:10.0

Trust: 1.0

vendor:hcltechmodel:dominoscope:eqversion:9.0

Trust: 1.0

vendor:hcltechmodel:dominoscope:eqversion:11.0

Trust: 1.0

vendor:hclmodel:domino serverscope:eqversion:10.0

Trust: 0.8

vendor:hclmodel:domino serverscope:eqversion: -

Trust: 0.8

vendor:hclmodel:domino serverscope:eqversion:9.0

Trust: 0.8

vendor:hclmodel:domino serverscope: - version: -

Trust: 0.8

vendor:hclmodel:domino serverscope:eqversion:11.0

Trust: 0.8

sources: JVNDB: JVNDB-2022-010217 // NVD: CVE-2020-4107

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2020-4107
value: HIGH

Trust: 1.0

psirt@hcl.com: CVE-2020-4107
value: HIGH

Trust: 1.0

NVD: CVE-2020-4107
value: HIGH

Trust: 0.8

CNNVD: CNNVD-202105-758
value: HIGH

Trust: 0.6

nvd@nist.gov: CVE-2020-4107
severity: MEDIUM
baseScore: 4.6
vectorString: AV:L/AC:L/AU:N/C:P/I:P/A:P
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 3.9
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

nvd@nist.gov: CVE-2020-4107
baseSeverity: HIGH
baseScore: 7.8
vectorString: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 1.8
impactScore: 5.9
version: 3.1

Trust: 1.0

psirt@hcl.com: CVE-2020-4107
baseSeverity: HIGH
baseScore: 8.8
vectorString: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: CHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 2.0
impactScore: 6.0
version: 3.1

Trust: 1.0

NVD: CVE-2020-4107
baseSeverity: HIGH
baseScore: 7.8
vectorString: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: JVNDB: JVNDB-2022-010217 // CNNVD: CNNVD-202105-758 // NVD: CVE-2020-4107 // NVD: CVE-2020-4107

PROBLEMTYPE DATA

problemtype:NVD-CWE-Other

Trust: 1.0

problemtype:CWE-284

Trust: 1.0

problemtype:others (CWE-Other) [NVD evaluation ]

Trust: 0.8

sources: JVNDB: JVNDB-2022-010217 // NVD: CVE-2020-4107

THREAT TYPE

local

Trust: 0.6

sources: CNNVD: CNNVD-202105-758

TYPE

other

Trust: 0.6

sources: CNNVD: CNNVD-202105-758

PATCH

title:HCL Software HCL Domino Security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=150262

Trust: 0.6

sources: CNNVD: CNNVD-202105-758

EXTERNAL IDS

db:NVDid:CVE-2020-4107

Trust: 3.3

db:JVNDBid:JVNDB-2022-010217

Trust: 0.8

db:CNNVDid:CNNVD-202105-758

Trust: 0.6

db:VULMONid:CVE-2020-4107

Trust: 0.1

sources: VULMON: CVE-2020-4107 // JVNDB: JVNDB-2022-010217 // CNNVD: CNNVD-202105-758 // NVD: CVE-2020-4107

REFERENCES

url:https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=kb0090221

Trust: 2.5

url:https://nvd.nist.gov/vuln/detail/cve-2020-4107

Trust: 0.8

url:https://vigilance.fr/vulnerability/hcl-domino-privilege-escalation-35404

Trust: 0.6

url:https://cxsecurity.com/cveshow/cve-2020-4107/

Trust: 0.6

url:https://nvd.nist.gov

Trust: 0.1

sources: VULMON: CVE-2020-4107 // JVNDB: JVNDB-2022-010217 // CNNVD: CNNVD-202105-758 // NVD: CVE-2020-4107

SOURCES

db:VULMONid:CVE-2020-4107
db:JVNDBid:JVNDB-2022-010217
db:CNNVDid:CNNVD-202105-758
db:NVDid:CVE-2020-4107

LAST UPDATE DATE

2024-08-14T13:54:03.454000+00:00


SOURCES UPDATE DATE

db:VULMONid:CVE-2020-4107date:2022-05-20T00:00:00
db:JVNDBid:JVNDB-2022-010217date:2023-08-10T08:28:00
db:CNNVDid:CNNVD-202105-758date:2022-06-06T00:00:00
db:NVDid:CVE-2020-4107date:2022-09-20T19:20:05.127

SOURCES RELEASE DATE

db:VULMONid:CVE-2020-4107date:2022-05-19T00:00:00
db:JVNDBid:JVNDB-2022-010217date:2023-08-10T00:00:00
db:CNNVDid:CNNVD-202105-758date:2021-05-12T00:00:00
db:NVDid:CVE-2020-4107date:2022-05-19T22:15:07.943