CVE-2020-4126
Estado: ModificadaMedia (5.9)—
HCL iNotes is susceptible to a sensitive cookie exposure vulnerability. This can allow an unauthenticated remote attacker to capture the cookie by intercepting its transmission within an http session. Fixes are available in HCL Domino and iNotes versions 10.0.1 FP6 and 11.0.1 FP2 and later.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
- Puntuación base: 5.9
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.67%
- Percentil entre todas las CVEs puntuadas: 51
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-311
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2020-4126",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 4.3,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:P/I:N/A:N",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "MEDIUM",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.9,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 3.6,
"exploitabilityScore": 2.2
}
]
},
"affected": [
{
"source": "psirt@hcl.com",
"affectedData": [
{
"vendor": "n/a",
"product": "HCL iNotes",
"versions": [
{
"status": "affected",
"version": "v10.0.1 FP6, v11.0.1 FP2 and later"
}
]
}
]
}
],
"published": "2020-12-01T00:15:11.197",
"references": [
{
"url": "https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0085411",
"tags": [
"Vendor Advisory"
],
"source": "psirt@hcl.com"
},
{
"url": "https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0085411",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-311"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "HCL iNotes is susceptible to a sensitive cookie exposure vulnerability. This can allow an unauthenticated remote attacker to capture the cookie by intercepting its transmission within an http session. Fixes are available in HCL Domino and iNotes versions 10.0.1 FP6 and 11.0.1 FP2 and later."
},
{
"lang": "es",
"value": "HCL iNotes es susceptible a una vulnerabilidad de exposición de cookies confidenciales. Esto puede permitir a un atacante remoto no autenticado capturar la cookie interceptando su transmisión dentro de una sesión http. Las correcciones están disponibles en HCL Domino e iNotes versiones 10.0.1 FP6 y 11.0.1 FP2 y posteriores"
}
],
"lastModified": "2026-06-17T03:19:33.797",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:hcltech:hcl_inotes:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "281A8ED6-2F9B-493E-9E5B-E2CF8CAADE86",
"versionEndExcluding": "10.0.1",
"versionStartIncluding": "9.0"
},
{
"criteria": "cpe:2.3:a:hcltech:hcl_inotes:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "83B10D1E-A272-48A7-AB91-12CE7B909B6B",
"versionEndExcluding": "11.0.1",
"versionStartIncluding": "11.0.0"
},
{
"criteria": "cpe:2.3:a:hcltech:hcl_inotes:10.0.1:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6DB5111E-B70F-475F-A23D-DF08FD1AB97E"
},
{
"criteria": "cpe:2.3:a:hcltech:hcl_inotes:10.0.1:fixpack1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7AA0BE4B-C5B2-4F0A-AE23-25032CC7C2E3"
},
{
"criteria": "cpe:2.3:a:hcltech:hcl_inotes:10.0.1:fixpack2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AE8447C7-B040-461A-88AD-C407A3867928"
},
{
"criteria": "cpe:2.3:a:hcltech:hcl_inotes:10.0.1:fixpack3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "080E290A-A18E-45A6-9039-369763AC27CC"
},
{
"criteria": "cpe:2.3:a:hcltech:hcl_inotes:10.0.1:fixpack4:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EE08595A-7384-4DED-854F-B28C4C431FEC"
},
{
"criteria": "cpe:2.3:a:hcltech:hcl_inotes:10.0.1:fixpack5:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3971CAAD-A1A2-4EE9-9BC9-A7108E3B671C"
},
{
"criteria": "cpe:2.3:a:hcltech:hcl_inotes:11.0.1:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2433DEDD-8650-4B01-85B9-92F5D1446030"
},
{
"criteria": "cpe:2.3:a:hcltech:hcl_inotes:11.0.1:fixpack1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "582BCD88-43F2-4E10-B638-4C1D54ED71F8"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "psirt@hcl.com"
}