HCL Nomad server
cpe:2.3:a:hcltech:nomad_server_on_domino:*:*:*:*:*:*:*
- < 1.0.19
A vulnerability exists in HCL Nomad server on Domino versions prior to 1.0.19 due to the Content-Security-Policy header not including a default frame-ancestors directive. This omission could enable an attacker to access sensitive information through unspecified means.
The lack of a default frame-ancestors directive in the Content-Security-Policy header could allow for clickjacking attacks, potentially leading to the disclosure of sensitive information.
Users are advised to download the latest version of HCL Nomad server on Domino, which includes the corrected default response headers. Release notes for this version can be found in the HCL Nomad for web browsers and HCL Nomad server on Domino 1.0.x Release Notes.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.