The Top Updates implementation in the Homepage component in IBM Lotus Connections 2.5.x before 2.5.0.2, when "forced SSL" is enabled, uses http for links, which has unspecified impact and remote attack vectors.
References
Link | Resource |
---|---|
http://secunia.com/advisories/40007 | Vendor Advisory |
http://www-01.ibm.com/support/docview.wss?uid=swg21431472 | Patch Vendor Advisory |
http://www-1.ibm.com/support/docview.wss?uid=swg1LO48325 | |
http://www.vupen.com/english/advisories/2010/1281 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2010-06-15 14:30
Updated : 2010-06-16 04:00
NVD link : CVE-2010-2279
Mitre link : CVE-2010-2279
CVE.ORG link : CVE-2010-2279
JSON object : View
Products Affected
ibm
- lotus_connections
CWE