U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2023-37495

Change History

New CVE Received from HCL Software 2/28/2024 8:40:04 PM

Action Type Old Value New Value
Added Description

								
							
							
						
Internet passwords stored in Person documents in the Domino® Directory created using the "Add Person" action on the People & Groups tab in the Domino® Administrator are secured using a cryptographically weak hash algorithm.  This could enable attackers with access to the hashed value to determine a user's password, e.g. using a brute force attack.  This issue does not impact Person documents created through  user registration https://help.hcltechsw.com/domino/10.0.1/admin/conf_userregistration_c.html . 
Added CVSS V3.1

								
							
							
						
HCL Software AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Added Reference

								
							
							
						
HCL Software https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0107585 [No types assigned]