Lucene search

K
cveMitreCVE-2010-2278
HistoryJun 15, 2010 - 2:30 p.m.

CVE-2010-2278

2010-06-1514:30:01
mitre
web.nvd.nist.gov
25
ibm
lotus connections
cve-2010-2278
bookmarklet
ssl
network sniffing
man-in-the-middle
security vulnerability

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:H/Au:N/C:P/I:P/A:N

AI Score

6.6

Confidence

Low

EPSS

0.004

Percentile

72.4%

The bookmarklet pop-up in the Bookmarks component in IBM Lotus Connections 2.5.x before 2.5.0.2 does not properly follow the “force SSL” setting, which might make it easier for remote attackers to obtain the cleartext of network communication by sniffing the network, or spoof arbitrary servers via a man-in-the-middle attack.

Affected configurations

Nvd
Node
ibmlotus_connectionsMatch2.5.0
OR
ibmlotus_connectionsMatch2.5.0.1
VendorProductVersionCPE
ibmlotus_connections2.5.0cpe:2.3:a:ibm:lotus_connections:2.5.0:*:*:*:*:*:*:*
ibmlotus_connections2.5.0.1cpe:2.3:a:ibm:lotus_connections:2.5.0.1:*:*:*:*:*:*:*

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:H/Au:N/C:P/I:P/A:N

AI Score

6.6

Confidence

Low

EPSS

0.004

Percentile

72.4%

Related for CVE-2010-2278