4
CVSSv2

CVE-2010-2278

Published: 15/06/2010 Updated: 16/06/2010
CVSS v2 Base Score: 4 | Impact Score: 4.9 | Exploitability Score: 4.9
VMScore: 356
Vector: AV:N/AC:H/Au:N/C:P/I:P/A:N

Vulnerability Summary

The bookmarklet pop-up in the Bookmarks component in IBM Lotus Connections 2.5.x prior to 2.5.0.2 does not properly follow the "force SSL" setting, which might make it easier for remote malicious users to obtain the cleartext of network communication by sniffing the network, or spoof arbitrary servers via a man-in-the-middle attack.

Vulnerable Product Search on Vulmon Subscribe to Product

ibm lotus connections 2.5.0

ibm lotus connections 2.5.0.1