VYPR
Medium severity5.9NVD Advisory· Published Aug 29, 2022· Updated Jun 17, 2026

CVE-2022-27558

CVE-2022-27558

Description

HCL iNotes is susceptible to a Broken Password Strength Checks vulnerability. Custom password policies are not enforced on certain iNotes forms which could allow users to set weak passwords, leading to easier cracking.

Affected products

6
  • HCLTech/Domino2 versions
    cpe:2.3:a:hcltech:domino:12.0.1:-:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:hcltech:domino:12.0.1:-:*:*:*:*:*:*
    • cpe:2.3:a:hcltech:domino:12.0.1:fixpack_1:*:*:*:*:*:*
  • cpe:2.3:a:hcltech:hcl_inotes:12.0.1:-:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:hcltech:hcl_inotes:12.0.1:-:*:*:*:*:*:*
    • cpe:2.3:a:hcltech:hcl_inotes:12.0.1:fixpack_1:*:*:*:*:*:*
  • HCL Software/iNotesllm-create2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: 12.0.1, 12.0.1FP1

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.