CVE-2011-1032
IBM Lotus Connections 3.0 - Unauthenticated Access to Internal Login Module
Title source: llmDescription
IBM Lotus Connections 3.0, when IBM WebSphere Application Server 7.0.0.11 is used, does not properly restrict access to the internal login module, which has unspecified impact and attack vectors.
References (5)
Core 5
Core References
Various Sources x_refsource_confirm
http://www.ibm.com/support/docview.wss?uid=swg21462435
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://osvdb.org/70931
Third Party Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2011/0382
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/43298
Various Sources vendor-advisory
x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=swg1PK54565
Scores
EPSS
0.0144
EPSS Percentile
70.5%
Details
CWE
CWE-264
Status
published
Products (1)
ibm/lotus_connections
3.0
Published
Feb 15, 2011
Tracked Since
Feb 18, 2026