cbcvebase.
CVE-2010-2278
published 2010-06-15

CVE-2010-2278: The bookmarklet pop-up in the Bookmarks component in IBM Lotus Connections 2.5.x before 2.5.0.2 does not properly follow the "force SSL" setting, which might…

PriorityP421medium4CVSS 2.0
AVNACHAuNCPIPAN
EPSS
1.42%
69.7th percentile
The bookmarklet pop-up in the Bookmarks component in IBM Lotus Connections 2.5.x before 2.5.0.2 does not properly follow the "force SSL" setting, which might make it easier for remote attackers to obtain the cleartext of network communication by sniffing the network, or spoof arbitrary servers via a man-in-the-middle attack.

Affected

2 ranges
VendorProductVersion rangeFixed in
ibmlotus_connections
ibmlotus_connections
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.