Description
The Top Updates implementation in the Homepage component in IBM Lotus Connections 2.5.x before 2.5.0.2, when "forced SSL" is enabled, uses http for links, which has unspecified impact and remote attack vectors.
References (4)
Core 4
Core References
Various Sources vendor-advisory
x_refsource_aixapar
http://www-1.ibm.com/support/docview.wss?uid=swg1LO48325
Vendor Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2010/1281
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/40007
Patch, Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21431472
Scores
EPSS
0.0126
EPSS Percentile
66.7%
Details
Status
published
Products (2)
ibm/lotus_connections
2.5.0
ibm/lotus_connections
2.5.0.1
Published
Jun 15, 2010
Tracked Since
Feb 18, 2026