« Volver al listado

CVE-2022-44752

Estado: ModificadaAlta (7.8)—

HCL Domino is susceptible to a stack based buffer overflow vulnerability in wp6sr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted WordPerfect file.  This vulnerability applies to software previously licensed by IBM.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-44752",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2022-44752",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-04-17T15:19:35.577657Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "psirt@hcl.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "psirt@hcl.com",
      "affectedData": [
        {
          "vendor": "HCL Software",
          "product": "Domino",
          "versions": [
            {
              "status": "affected",
              "version": "9"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2022-12-19T11:15:10.950",
  "references": [
    {
      "url": "https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0102151",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "psirt@hcl.com"
    },
    {
      "url": "https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0102151",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-787"
        }
      ]
    },
    {
      "type": "Secondary",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "description": [
        {
          "lang": "en",
          "value": "CWE-787"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "HCL Domino is susceptible to a stack based buffer overflow vulnerability in wp6sr.dll in Micro Focus KeyView.  This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted WordPerfect file.  This vulnerability applies to software previously licensed by IBM.\n"
    },
    {
      "lang": "es",
      "value": "HCL Domino es susceptible a una vulnerabilidad de desbordamiento del búfer basada en pila en wp6sr.dll en Micro Focus KeyView. Esto podría permitir que un atacante remoto no autenticado bloquee la aplicación o ejecute código arbitrario a través de un archivo WordPerfect manipulado. Esta vulnerabilidad se aplica al software con licencia previa de IBM."
    }
  ],
  "lastModified": "2026-06-17T05:08:53.490",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:hcltech:domino:9.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0F1C7C9C-2F6E-4A82-BC16-B04E53B11E20"
            },
            {
              "criteria": "cpe:2.3:a:hcltech:domino:9.0.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A73B2674-F58B-46AB-94E6-5B83886C25A5"
            },
            {
              "criteria": "cpe:2.3:a:hcltech:domino:9.0.1:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4E0BF886-B732-4210-82AA-4D2B3F77132B"
            },
            {
              "criteria": "cpe:2.3:a:hcltech:domino:9.0.1:feature_pack_10_interim_fix_3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2D00AC8D-4E35-49F4-B0EE-C03E1EE67B8E"
            },
            {
              "criteria": "cpe:2.3:a:hcltech:domino:9.0.1:feature_pack_10_interim_fix_4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0FBD1792-01BA-402A-859E-531F7614C9A2"
            },
            {
              "criteria": "cpe:2.3:a:hcltech:domino:9.0.1:feature_pack_10_interim_fix_5:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DB652BE0-5767-4D42-A618-1315243A5C52"
            },
            {
              "criteria": "cpe:2.3:a:hcltech:domino:9.0.1:feature_pack_8:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F3D799A2-AC87-43E8-A6A2-E76E1535A7C4"
            },
            {
              "criteria": "cpe:2.3:a:hcltech:domino:9.0.1:feature_pack_8_interim_fix_1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9C9A93C4-70E8-472D-A038-14F72780E02F"
            },
            {
              "criteria": "cpe:2.3:a:hcltech:domino:9.0.1:feature_pack_8_interim_fix_2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "442C02A0-0232-488A-8A66-62386FFBC807"
            },
            {
              "criteria": "cpe:2.3:a:hcltech:domino:9.0.1:feature_pack_8_interim_fix_3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A349B3BD-CB3D-4290-BE9E-8FFA68C3512B"
            },
            {
              "criteria": "cpe:2.3:a:hcltech:domino:9.0.1:fixpack_10:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "866FCD8A-56FE-4D00-A9F6-F83D3400CF91"
            },
            {
              "criteria": "cpe:2.3:a:hcltech:domino:9.0.1:fixpack_3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9F8486D8-494D-45B0-8447-F1EDB8C2F8A5"
            },
            {
              "criteria": "cpe:2.3:a:hcltech:domino:9.0.1:fixpack_4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "19CC1B88-ED3D-4AD0-8B06-C75D198E1BB3"
            },
            {
              "criteria": "cpe:2.3:a:hcltech:domino:9.0.1:fixpack_5:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C76546DF-A75A-489C-80D8-D1372F2FF586"
            },
            {
              "criteria": "cpe:2.3:a:hcltech:domino:9.0.1:fixpack_6:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C49C0CA8-485E-4748-A5D5-C3B5FF98381E"
            },
            {
              "criteria": "cpe:2.3:a:hcltech:domino:9.0.1:fixpack_7:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2C1D2585-833B-4A5A-AAF3-3215C52FE73A"
            },
            {
              "criteria": "cpe:2.3:a:hcltech:domino:9.0.1:fixpack_8:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AAAE216E-780B-48A7-89D9-6FB8E799B78C"
            },
            {
              "criteria": "cpe:2.3:a:hcltech:domino:9.0.1:fixpack_9:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A44BBF13-7FCF-4CD9-8EA7-C20CA701B8BA"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "psirt@hcl.com"
}