Filtered by vendor Hcltech Subscriptions
Filtered by product Domino Subscriptions
Total 22 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2022-38654 1 Hcltech 1 Domino 2024-08-03 5.5 Medium
HCL Domino is susceptible to an information disclosure vulnerability. In some scenarios, local calls made on the server to search the Domino directory will ignore xACL read restrictions. An authenticated attacker could leverage this vulnerability to access attributes from a user's person record.
CVE-2023-37539 1 Hcltech 1 Domino 2024-08-02 8.4 High
The Domino Catalog template is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability. An attacker with the ability to edit documents in the catalog application/database created from this template can embed a cross site scripting attack. The attack would be activated by an end user clicking it.