VulnerabilityModified
CVE-2010-2279
The Top Updates implementation in the Homepage component in IBM Lotus Connections 2.5.x before 2.5.0.2, when "forced SSL" is enabled, uses http for links, which has unspecified impact and remote attack vectors.
HIGH 7.6EPSS 1.26%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.26%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The Top Updates implementation in the Homepage component in IBM Lotus Connections 2.5.x before 2.5.0.2, when "forced SSL" is enabled, uses http for links, which has unspecified impact and remote attack vectors.
- CVSS 2.0
- 7.6 HIGHAV:N/AC:H/Au:N/C:C/I:C/A:C
- EPSS
- 1.26% probability · 68th percentile
- CISA KEV
- Not listed
- Affected
- ibm/lotus connections
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/40007Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21431472Patch, Vendor Advisory
- http://www-1.ibm.com/support/docview.wss?uid=swg1LO48325
- http://www.vupen.com/english/advisories/2010/1281Vendor Advisory
- http://secunia.com/advisories/40007Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21431472Patch, Vendor Advisory
- http://www-1.ibm.com/support/docview.wss?uid=swg1LO48325
- http://www.vupen.com/english/advisories/2010/1281Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.