Buffer overflow in HCL Notes - CVE-2020-4102

 

Buffer overflow in HCL Notes - CVE-2020-4102

Published: December 2, 2020 / Updated: December 3, 2020


Vulnerability identifier: #VU48771
CSH Severity: Low
CVSS v4: 5.4 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-4102
CWE-ID: CWE-119
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error within the DXL input parameter. A local administrator can send a specially crafted request, trigger memory corruption and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

HCL Notes

How to mitigate CVE-2020-4102

Install updates from vendor's website.

HCL Notes - addressed in versions 10.0.1 FP6, 11.0.1 FP2

External References

Related Security Bulletins