VulnerabilityModified
CVE-2011-1032
IBM Lotus Connections 3.0, when IBM WebSphere Application Server 7.0.0.11 is used, does not properly restrict access to the internal login module, which has unspecified impact and attack vectors.
MEDIUM 6.8EPSS 1.44%
Does this matter?
Lower severity and a low EPSS score (1.44%). Track it; it rarely justifies an emergency change on its own.
Description
IBM Lotus Connections 3.0, when IBM WebSphere Application Server 7.0.0.11 is used, does not properly restrict access to the internal login module, which has unspecified impact and attack vectors.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 1.44% probability · 72th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- ibm/lotus connections
- Source
- cve@mitre.org
References
- http://osvdb.org/70931
- http://secunia.com/advisories/43298Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg1PK54565
- http://www.ibm.com/support/docview.wss?uid=swg21462435
- http://www.vupen.com/english/advisories/2011/0382
- http://osvdb.org/70931
- http://secunia.com/advisories/43298Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg1PK54565
- http://www.ibm.com/support/docview.wss?uid=swg21462435
- http://www.vupen.com/english/advisories/2011/0382
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.