Inotes
Vendor:
First CVE: Feb 1, 2017 · Active for 9 years
20
Total CVEs
More Total CVEs than 94% of tracked products
6.7
Avg CVEs / Year
Higher CVE frequency than 92% of tracked products
6.1
Avg CVSS
Higher Avg CVSS than 24% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Inotes over time
Volume of CVEsAvg CVSS Base Score
First CVE
Feb 1, 2017
9 years ago
Most Recent CVE
Jul 1, 2020
2,214 days ago
CVE Severity & Scoring
Inotes20 CVEs
95%
All CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network20 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low20 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None1 (5.0%)
Unknown0 (0.0%)
Required19 (95.0%)
Privileges Required
Low3 (15.0%)
High0 (0.0%)
None17 (85.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (20 CVEs).
20 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-1129MEDIUM IBM Notes 8.5 and 9.0 is vulnerable to a denial of service. If a user is persuaded to click on a malicious link, it could cause the Notes client to hang and have to be restarted. I | Sep 5, 2017 | 6.5 | 50 | NO | YES |
CVE-2017-1130MEDIUM IBM Notes 8.5 and 9.0 is vulnerable to a denial of service. If a user is persuaded to click on a malicious link, it would open up many file select dialog boxes which would cause th | Sep 5, 2017 | 6.5 | 49 | NO | YES |
CVE-2017-1659MEDIUM "HCL iNotes is susceptible to a Cross-Site Scripting (XSS) Vulnerability. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials." | Jul 1, 2020 | 6.1 | 22 | NO | NO |
CVE-2017-1421MEDIUM IBM iNotes is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentia | Dec 13, 2017 | 6.1 | 22 | NO | NO |
CVE-2017-1325MEDIUM IBM iNotes 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functional | May 26, 2017 | 6.1 | 22 | NO | NO |
CVE-2016-9990MEDIUM IBM iNotes 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functional | Mar 31, 2017 | 6.1 | 22 | NO | NO |
CVE-2016-2939MEDIUM IBM iNotes is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentia | Feb 1, 2017 | 6.1 | 22 | NO | NO |
CVE-2016-2938MEDIUM IBM iNotes is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentia | Feb 1, 2017 | 6.1 | 22 | NO | NO |
CVE-2013-0594MEDIUM Open redirect vulnerability in IBM iNotes before 8.5.3 Fix Pack 6 and 9.x before 9.0.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks | Jul 11, 2018 | 6.1 | 21 | NO | NO |
CVE-2017-1332MEDIUM IBM iNotes 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functional | Jul 31, 2017 | 6.1 | 21 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (20 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
2 CVEs
10.0% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
10.0% of CVEs· 89th percentile
Social Chatter
Signals from CVEs in this product scope (20 CVEs).
Media Mentions
Signals from CVEs in this product scope (20 CVEs).
Top CNAs Publishing CVEs For Inotes
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 9.0.1.8 | 5 | 6.3 | 12.5% | 0 | 2 |
| 9.0.1.7 | 2 | 5.9 | 1.1% | 0 | 0 |
| 9.0.1.6 | 11 | 6.0 | 1.0% | 0 | 0 |
| 9.0.1.5 | 11 | 6.0 | 1.0% | 0 | 0 |
| 9.0.1.4 | 11 | 6.0 | 1.0% | 0 | 0 |
| 9.0.1.3 | 11 | 6.0 | 1.0% | 0 | 0 |
| 9.0.1.2 | 11 | 6.0 | 1.0% | 0 | 0 |
| 9.0.1.1 | 16 | 6.1 | 4.6% | 0 | 2 |
| 9.0.1.0 | 15 | 6.1 | 4.8% | 0 | 2 |
| 9.0.1 | 1 | 6.1 | 1.1% | 0 | 0 |
| 9.0.0.0 | 18 | 6.1 | 4.2% | 0 | 2 |
| 9.0 | 1 | 6.1 | 1.1% | 0 | 0 |
| 8.5.3.6 | 14 | 6.1 | 5.1% | 0 | 2 |
| 8.5.3.5 | 11 | 6.0 | 1.0% | 0 | 0 |
| 8.5.3.4 | 11 | 6.0 | 1.0% | 0 | 0 |
| 8.5.3.3 | 11 | 6.0 | 1.0% | 0 | 0 |
| 8.5.3.2 | 11 | 6.0 | 1.0% | 0 | 0 |
| 8.5.3.1 | 16 | 6.1 | 4.6% | 0 | 2 |
| 8.5.3.0 | 18 | 6.1 | 4.2% | 0 | 2 |
| 8.5.3 | 1 | 6.1 | 1.1% | 0 | 0 |