VYPR
Medium severity5.5NVD Advisory· Published Nov 4, 2022· Updated Jun 17, 2026

CVE-2022-38654

CVE-2022-38654

Description

HCL Domino is susceptible to an information disclosure vulnerability. In some scenarios, local calls made on the server to search the Domino directory will ignore xACL read restrictions. An authenticated attacker could leverage this vulnerability to access attributes from a user's person record.

Affected products

33
  • HCLTech/Domino31 versions
    cpe:2.3:a:hcltech:domino:10.0.0:*:*:*:*:*:*:*+ 30 more
    • cpe:2.3:a:hcltech:domino:10.0.0:*:*:*:*:*:*:*
    • cpe:2.3:a:hcltech:domino:10.0.1:-:*:*:*:*:*:*
    • cpe:2.3:a:hcltech:domino:10.0.1:fixpack_1:*:*:*:*:*:*
    • cpe:2.3:a:hcltech:domino:10.0.1:fixpack_2:*:*:*:*:*:*
    • cpe:2.3:a:hcltech:domino:10.0.1:fixpack_3:*:*:*:*:*:*
    • cpe:2.3:a:hcltech:domino:10.0.1:fixpack_4:*:*:*:*:*:*
    • cpe:2.3:a:hcltech:domino:10.0.1:fixpack_5:*:*:*:*:*:*
    • cpe:2.3:a:hcltech:domino:10.0.1:fixpack_6:*:*:*:*:*:*
    • cpe:2.3:a:hcltech:domino:10.0.1:fixpack_7:*:*:*:*:*:*
    • cpe:2.3:a:hcltech:domino:11.0.1:-:*:*:*:*:*:*
    • cpe:2.3:a:hcltech:domino:11.0.1:fixpack_1:*:*:*:*:*:*
    • cpe:2.3:a:hcltech:domino:11.0.1:fixpack_2:*:*:*:*:*:*
    • cpe:2.3:a:hcltech:domino:11.0.1:fixpack_3:*:*:*:*:*:*
    • cpe:2.3:a:hcltech:domino:11.0.1:fixpack_4:*:*:*:*:*:*
    • cpe:2.3:a:hcltech:domino:11.0.1:fixpack_5:*:*:*:*:*:*
    • cpe:2.3:a:hcltech:domino:12.0:*:*:*:*:*:*:*
    • cpe:2.3:a:hcltech:domino:9.0.1:-:*:*:*:*:*:*
    • cpe:2.3:a:hcltech:domino:9.0.1:feature_pack_10_interim_fix_3:*:*:*:*:*:*
    • cpe:2.3:a:hcltech:domino:9.0.1:feature_pack_10_interim_fix_4:*:*:*:*:*:*
    • cpe:2.3:a:hcltech:domino:9.0.1:feature_pack_10_interim_fix_5:*:*:*:*:*:*
    • cpe:2.3:a:hcltech:domino:9.0.1:feature_pack_8:*:*:*:*:*:*
    • cpe:2.3:a:hcltech:domino:9.0.1:feature_pack_8_interim_fix_1:*:*:*:*:*:*
    • cpe:2.3:a:hcltech:domino:9.0.1:feature_pack_8_interim_fix_2:*:*:*:*:*:*
    • cpe:2.3:a:hcltech:domino:9.0.1:feature_pack_8_interim_fix_3:*:*:*:*:*:*
    • cpe:2.3:a:hcltech:domino:9.0.1:fixpack_3:*:*:*:*:*:*
    • cpe:2.3:a:hcltech:domino:9.0.1:fixpack_4:*:*:*:*:*:*
    • cpe:2.3:a:hcltech:domino:9.0.1:fixpack_5:*:*:*:*:*:*
    • cpe:2.3:a:hcltech:domino:9.0.1:fixpack_6:*:*:*:*:*:*
    • cpe:2.3:a:hcltech:domino:9.0.1:fixpack_7:*:*:*:*:*:*
    • cpe:2.3:a:hcltech:domino:9.0.1:fixpack_8:*:*:*:*:*:*
    • cpe:2.3:a:hcltech:domino:9.0.1:fixpack_9:*:*:*:*:*:*
  • HCL Software/Dominollm-create2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: 9, 10, 11, 12

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.