← Back

CVE-2022-38660

nvd nist
Published: Nov 4, 2022Modified: Jun 17, 2026

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

HCL XPages applications are susceptible to a Cross Site Request Forgery (CSRF) vulnerability. An unauthenticated attacker could exploit this vulnerability to perform actions in the application on behalf of the logged in user.  

Affected (8)

Products: Hcltech: Domino
1 product
Domino
Configuration A
8 vulnerable
Vulnerable SoftwareAffected Versions
Hcltech
Before 9.0.1
Version 9.0.1 feature_pack_10_interim_fix_3
Version 9.0.1 feature_pack_10_interim_fix_4
Version 9.0.1 feature_pack_10_interim_fix_5
Version 9.0.1 feature_pack_8
Version 9.0.1 feature_pack_8_interim_fix_1
Version 9.0.1 feature_pack_8_interim_fix_2
Version 9.0.1 feature_pack_8_interim_fix_3

References (2)

Timeline

No history available yet.