6.5
CVSSv3

CVE-2020-4089

Published: 26/06/2020 Updated: 21/07/2021
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

HCL Notes is vulnerable to an information leakage vulnerability through its support for the 'mailto' protocol. This vulnerability could result in files from the user's filesystem or connected network filesystems being leaked to a third party. All versions of HCL Notes 9, 10 and 11 are affected.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

hcltech notes 9.0

hcltech notes 10.0

hcltech notes 11.0

Recent Articles

Pretty wild that a malicious mailto: link might attach your secret keys and files from your PC to an outgoing message
The Register • Thomas Claburn in San Francisco • 19 Aug 2020

Some OpenPGP, S/MIME-capable email clients vulnerable to attack Open-source 64-ish-bit serial number gen snafu sparks TLS security cert revoke runaround

Boffins testing the security of OpenPGP and S/MIME, two end-to-end encryption schemes for email, recently found multiple vulnerabilities in the way email client software deals with certificates and key exchange mechanisms. They found that five out of 18 OpenPGP-capable email clients and six out of 18 S/MIME-capable clients are vulnerable to at least one attack. These flaws are not due to cryptographic weaknesses. Rather they arise from the complexity of email infrastructure, based on dozens of s...

Pretty wild that a malicious mailto: link might attach your secret keys and files from your PC to an outgoing message
The Register • Thomas Claburn in San Francisco • 19 Aug 2020

Some OpenPGP, S/MIME-capable email clients vulnerable to attack Open-source 64-ish-bit serial number gen snafu sparks TLS security cert revoke runaround

Boffins testing the security of OpenPGP and S/MIME, two end-to-end encryption schemes for email, recently found multiple vulnerabilities in the way email client software deals with certificates and key exchange mechanisms. They found that five out of 18 OpenPGP-capable email clients and six out of 18 S/MIME-capable clients are vulnerable to at least one attack. These flaws are not due to cryptographic weaknesses. Rather they arise from the complexity of email infrastructure, based on dozens of s...