Inotes

Vendor:

First CVE: Feb 1, 2017 · Active for 9 years

20
Total CVEs
More Total CVEs than 94% of tracked products
6.7
Avg CVEs / Year
Higher CVE frequency than 92% of tracked products
6.1
Avg CVSS
Higher Avg CVSS than 24% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Inotes over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 1, 2017
9 years ago
Most Recent CVE
Jul 1, 2020
2,214 days ago

CVE Severity & Scoring

Inotes20 CVEs
All CVEs352,231 CVEs
MediumHigh
Attack Vector
Local0 (0.0%)
Network20 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low20 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None1 (5.0%)
Unknown0 (0.0%)
Required19 (95.0%)
Privileges Required
Low3 (15.0%)
High0 (0.0%)
None17 (85.0%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (20 CVEs).

20 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
IBM Notes 8.5 and 9.0 is vulnerable to a denial of service. If a user is persuaded to click on a malicious link, it could cause the Notes client to hang and have to be restarted. I
Sep 5, 20176.550NOYES
IBM Notes 8.5 and 9.0 is vulnerable to a denial of service. If a user is persuaded to click on a malicious link, it would open up many file select dialog boxes which would cause th
Sep 5, 20176.549NOYES
"HCL iNotes is susceptible to a Cross-Site Scripting (XSS) Vulnerability. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials."
Jul 1, 20206.122NONO
IBM iNotes is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentia
Dec 13, 20176.122NONO
IBM iNotes 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functional
May 26, 20176.122NONO
IBM iNotes 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functional
Mar 31, 20176.122NONO
IBM iNotes is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentia
Feb 1, 20176.122NONO
IBM iNotes is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentia
Feb 1, 20176.122NONO
Open redirect vulnerability in IBM iNotes before 8.5.3 Fix Pack 6 and 9.x before 9.0.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks
Jul 11, 20186.121NONO
IBM iNotes 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functional
Jul 31, 20176.121NONO

Exploit Exposure

Signals from CVEs in this product scope (20 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
2 CVEs
10.0% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
10.0% of CVEs· 89th percentile

Social Chatter

Signals from CVEs in this product scope (20 CVEs).

Media Mentions

Signals from CVEs in this product scope (20 CVEs).

Top CNAs Publishing CVEs For Inotes

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
9.0.1.856.312.5%02
9.0.1.725.91.1%00
9.0.1.6116.01.0%00
9.0.1.5116.01.0%00
9.0.1.4116.01.0%00
9.0.1.3116.01.0%00
9.0.1.2116.01.0%00
9.0.1.1166.14.6%02
9.0.1.0156.14.8%02
9.0.116.11.1%00
9.0.0.0186.14.2%02
9.016.11.1%00
8.5.3.6146.15.1%02
8.5.3.5116.01.0%00
8.5.3.4116.01.0%00
8.5.3.3116.01.0%00
8.5.3.2116.01.0%00
8.5.3.1166.14.6%02
8.5.3.0186.14.2%02
8.5.316.11.1%00