Internet passwords stored in Person documents in the Domino® Directory created using the "Add Person" action on the People & Groups tab in the Domino® Administrator are secured using a cryptographically weak hash algorithm. This could enable attackers with access to the hashed value to determine a user's password, e.g. using a brute force attack. This issue does not impact Person documents created through user registration https://help.hcltechsw.com/domino/10.0.1/admin/conf_userregistration_c.html .
Metrics
Affected Vendors & Products
References
History
Tue, 05 Nov 2024 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-306 | |
Metrics |
ssvc
|
MITRE
Status: PUBLISHED
Assigner: HCL
Published: 2024-02-20T18:22:21.038Z
Updated: 2024-11-05T17:56:44.670Z
Reserved: 2023-07-06T16:11:32.537Z
Link: CVE-2023-37495
Vulnrichment
Updated: 2024-08-02T17:16:30.243Z
NVD
Status : Awaiting Analysis
Published: 2024-02-29T01:40:04.220
Modified: 2024-11-05T18:35:02.867
Link: CVE-2023-37495
Redhat
No data.