CVE-2023-28015: Hcl Domino Appdev Pack
Medium severity, CVSS 5.3. EPSS: 0.5% chance of exploitation in the next 30 days.
The HCL Domino AppDev Pack IAM service is susceptible to a User Account Enumeration vulnerability. During a failed login attempt a difference in messages could allow an attacker to determine if the user is valid or not. The attacker could use this information to focus a brute force attack on valid users.
Affected products
- Hcl Domino Appdev Pack: before 1.0.16 (fixed in 1.0.16)
Published 2023-05-23. Last modified 2026-06-17.