The Top Updates implementation in the Homepage component in IBM Lotus Connections 2.5.x before 2.5.0.2, when "forced SSL" is enabled, uses http for links, which has unspecified impact and remote attack vectors.
References
Link | Resource |
---|---|
http://www-01.ibm.com/support/docview.wss?uid=swg21431472 | Patch Vendor Advisory |
http://www.vupen.com/english/advisories/2010/1281 | Vendor Advisory |
http://www-1.ibm.com/support/docview.wss?uid=swg1LO48325 | |
http://secunia.com/advisories/40007 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2010-06-15 07:30
Updated : 2010-06-15 21:00
NVD link : CVE-2010-2279
Mitre link : CVE-2010-2279
JSON object : View
CWE
Products Affected
ibm
- lotus_connections