SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2010-2278

The bookmarklet pop-up in the Bookmarks component in IBM Lotus Connections 2.5.x before 2.5.0.2 does not properly follow the "force SSL" setting, which might make it easier for remote attackers to obtain the cleartext of network communication by…

MEDIUM 4.0EPSS 1.42%

Does this matter?

Lower severity and a low EPSS score (1.42%). Track it; it rarely justifies an emergency change on its own.

Description

The bookmarklet pop-up in the Bookmarks component in IBM Lotus Connections 2.5.x before 2.5.0.2 does not properly follow the "force SSL" setting, which might make it easier for remote attackers to obtain the cleartext of network communication by sniffing the network, or spoof arbitrary servers via a man-in-the-middle attack.

CVSS 2.0
4.0 MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:N
EPSS
1.42% probability · 71th percentile
CISA KEV
Not listed
Affected
ibm/lotus connections
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.