CVE-2020-4097 Details
Description
In HCL Notes version 9 previous to release 9.0.1 FixPack 10 Interim Fix 8, version 10 previous to release 10.0.1 FixPack 6 and version 11 previous to 11.0.1 FixPack 1, a vulnerability in the input parameter handling of the Notes Client could potentially be exploited by an attacker resulting in a buffer overflow. This could enable an attacker to crash HCL Notes or execute attacker-controlled code on the client.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0084796 | CVE | Vendor Advisory |
| https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0084796 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-120 | Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| hcltech notes | >= 9.0, <= 9.0.1 >= 11.0, <= 11.0.1 9.0.1 fp10 9.0.1 fp10if1 9.0.1 fp10if2 9.0.1 fp10if3 9.0.1 fp10if4 9.0.1 fp10if5 9.0.1 fp10if6 9.0.1 fp10if7 9.0.1 fp1if1 9.0.1 fp1if2 9.0.1 fp2if1 9.0.1 fp2if2 9.0.1 fp2if3 9.0.1 fp2if4 9.0.1 fp3if1 9.0.1 fp3if2 9.0.1 fp3if3 9.0.1 fp3if4 9.0.1 fp4if1 9.0.1 fp4if2 9.0.1 fp5if1 9.0.1 fp5if2 9.0.1 fp5if3 9.0.1 fp7if1 9.0.1 fp7if2 9.0.1 fp8if1 9.0.1 fp9if1 9.0.1 fp9if2 10.0.0 fp1 10.0.0 fp2 10.0.0 fp3 10.0.0 fp4 10.0.0 fp5 10.0.1 fp1 10.0.1 fp2 10.0.1 fp3 10.0.1 fp4 10.0.1 fp5 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Nov 19, 2020 | Initial Analysis | [email protected] |