VYPR
Medium severity5.9NVD Advisory· Published Dec 1, 2020· Updated Jun 17, 2026

CVE-2020-4126

CVE-2020-4126

Description

HCL iNotes is susceptible to a sensitive cookie exposure vulnerability. This can allow an unauthenticated remote attacker to capture the cookie by intercepting its transmission within an http session. Fixes are available in HCL Domino and iNotes versions 10.0.1 FP6 and 11.0.1 FP2 and later.

Affected products

11
  • cpe:2.3:a:hcltech:hcl_inotes:*:*:*:*:*:*:*:*+ 8 more
    • cpe:2.3:a:hcltech:hcl_inotes:*:*:*:*:*:*:*:*range: >=9.0,<10.0.1
    • cpe:2.3:a:hcltech:hcl_inotes:10.0.1:-:*:*:*:*:*:*
    • cpe:2.3:a:hcltech:hcl_inotes:10.0.1:fixpack1:*:*:*:*:*:*
    • cpe:2.3:a:hcltech:hcl_inotes:10.0.1:fixpack2:*:*:*:*:*:*
    • cpe:2.3:a:hcltech:hcl_inotes:10.0.1:fixpack3:*:*:*:*:*:*
    • cpe:2.3:a:hcltech:hcl_inotes:10.0.1:fixpack4:*:*:*:*:*:*
    • cpe:2.3:a:hcltech:hcl_inotes:10.0.1:fixpack5:*:*:*:*:*:*
    • cpe:2.3:a:hcltech:hcl_inotes:11.0.1:-:*:*:*:*:*:*
    • cpe:2.3:a:hcltech:hcl_inotes:11.0.1:fixpack1:*:*:*:*:*:*
  • HCL/iNotesdescription
  • Range: before 10.0.1 FP6 and 11.0.1 FP2

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.