CVE-2011-1032

IBM Lotus Connections 3.0 - Unauthenticated Access to Internal Login Module

Title source: llm
STIX 2.1

Description

IBM Lotus Connections 3.0, when IBM WebSphere Application Server 7.0.0.11 is used, does not properly restrict access to the internal login module, which has unspecified impact and attack vectors.

References (5)

Core 5
Core References
Various Sources x_refsource_confirm
http://www.ibm.com/support/docview.wss?uid=swg21462435
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/70931
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2011/0382
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/43298
Various Sources vendor-advisory x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=swg1PK54565

Scores

EPSS 0.0144
EPSS Percentile 70.5%

Details

CWE
CWE-264
Status published
Products (1)
ibm/lotus_connections 3.0
Published Feb 15, 2011
Tracked Since Feb 18, 2026