Ibm Lotus Connections vulnerabilities

14 known vulnerabilities affecting ibm/lotus_connections.

Total CVEs
14
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH2MEDIUM10LOW1

Vulnerabilities

Page 1 of 1
CVE-2013-0503MEDIUMCVSS 4.3≤ 4.0.0.0v1.0.0.0+11 more2013-04-23
CVE-2013-0503 [MEDIUM] CWE-79 CVE-2013-0503: Cross-site scripting (XSS) vulnerability in the Bookmarks component in IBM Lotus Connections before Cross-site scripting (XSS) vulnerability in the Bookmarks component in IBM Lotus Connections before 4.0 CR3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2011-1032MEDIUMCVSS 6.8v3.02011-02-15
CVE-2011-1032 [MEDIUM] CWE-264 CVE-2011-1032: IBM Lotus Connections 3.0, when IBM WebSphere Application Server 7.0.0.11 is used, does not properly IBM Lotus Connections 3.0, when IBM WebSphere Application Server 7.0.0.11 is used, does not properly restrict access to the internal login module, which has unspecified impact and attack vectors.
nvd
CVE-2011-1030MEDIUMCVSS 4.3v3.02011-02-14
CVE-2011-1030 [MEDIUM] CWE-79 CVE-2011-1030: Cross-site scripting (XSS) vulnerability in the Wikis component in IBM Lotus Connections 3.0 allows Cross-site scripting (XSS) vulnerability in the Wikis component in IBM Lotus Connections 3.0 allows remote attackers to inject arbitrary web script or HTML via vectors related to the "Confirm New Page scene."
nvd
CVE-2010-2279HIGHCVSS 7.6v2.5.0v2.5.0.12010-06-15
CVE-2010-2279 [HIGH] CVE-2010-2279: The Top Updates implementation in the Homepage component in IBM Lotus Connections 2.5.x before 2.5.0 The Top Updates implementation in the Homepage component in IBM Lotus Connections 2.5.x before 2.5.0.2, when "forced SSL" is enabled, uses http for links, which has unspecified impact and remote attack vectors.
nvd
CVE-2010-2278MEDIUMCVSS 4.0v2.5.0v2.5.0.12010-06-15
CVE-2010-2278 [MEDIUM] CVE-2010-2278: The bookmarklet pop-up in the Bookmarks component in IBM Lotus Connections 2.5.x before 2.5.0.2 does The bookmarklet pop-up in the Bookmarks component in IBM Lotus Connections 2.5.x before 2.5.0.2 does not properly follow the "force SSL" setting, which might make it easier for remote attackers to obtain the cleartext of network communication by sniffing the network, or spoof arbitrary servers via a man-in-the-middle attack.
nvd
CVE-2010-2280MEDIUMCVSS 4.3v2.5.0v2.5.0.12010-06-15
CVE-2010-2280 [MEDIUM] CVE-2010-2280: Open redirect vulnerability in the Mobile component in IBM Lotus Connections 2.5.x before 2.5.0.2 al Open redirect vulnerability in the Mobile component in IBM Lotus Connections 2.5.x before 2.5.0.2 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors, related to "mobile edit actions," aka SPR ASRE83PPVH.
nvd
CVE-2010-2277MEDIUMCVSS 4.3v2.5.0v2.5.0.12010-06-15
CVE-2010-2277 [MEDIUM] CWE-79 CVE-2010-2277: Multiple cross-site scripting (XSS) vulnerabilities in IBM Lotus Connections 2.5.x before 2.5.0.2 al Multiple cross-site scripting (XSS) vulnerabilities in IBM Lotus Connections 2.5.x before 2.5.0.2 allow remote attackers to inject arbitrary web script or HTML via the (1) create or (2) edit form in the Communities component, the (3) verbiage field in the Bookmarks component, or (4) unspecified vectors related to the Mobile Blogs component.
nvd
CVE-2009-3816MEDIUMCVSS 4.3v2.5.0.02009-10-28
CVE-2009-3816 [MEDIUM] CWE-79 CVE-2009-3816: Multiple cross-site scripting (XSS) vulnerabilities in Activities pages in the Mobile subsystem in I Multiple cross-site scripting (XSS) vulnerabilities in Activities pages in the Mobile subsystem in IBM Lotus Connections 2.5.0.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2009-3469MEDIUMCVSS 4.3PoCv2.0.12009-09-29
CVE-2009-3469 [MEDIUM] CWE-79 CVE-2009-3469: Cross-site scripting (XSS) vulnerability in profiles/html/simpleSearch.do in IBM Lotus Connections 2 Cross-site scripting (XSS) vulnerability in profiles/html/simpleSearch.do in IBM Lotus Connections 2.0.1 allows remote attackers to inject arbitrary web script or HTML via the name parameter.
nvd
CVE-2008-4809CRITICALCVSS 10.0v2.02008-10-31
CVE-2008-4809 [CRITICAL] CVE-2008-4809: Multiple unspecified vulnerabilities in the Profiles search pages in IBM Lotus Connections 2.x befor Multiple unspecified vulnerabilities in the Profiles search pages in IBM Lotus Connections 2.x before 2.0.1 have unknown impact and attack vectors related to "Active" content. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
nvd
CVE-2008-4806HIGHCVSS 7.5≤ 2.0v1.0.22008-10-31
CVE-2008-4806 [HIGH] CWE-89 CVE-2008-4806: Multiple SQL injection vulnerabilities in IBM Lotus Connections 2.x before 2.0.1 allow remote attack Multiple SQL injection vulnerabilities in IBM Lotus Connections 2.x before 2.0.1 allow remote attackers to execute arbitrary SQL commands via the sortField parameter to unspecified components. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
nvd
CVE-2008-4805MEDIUMCVSS 4.3≤ 2.0v1.0.22008-10-31
CVE-2008-4805 [MEDIUM] CWE-79 CVE-2008-4805: Multiple cross-site scripting (XSS) vulnerabilities in IBM Lotus Connections 2.x before 2.0.1 allow Multiple cross-site scripting (XSS) vulnerabilities in IBM Lotus Connections 2.x before 2.0.1 allow remote attackers to inject arbitrary web script or HTML via (1) the community title, (2) API input, and vectors related to the (3) Homepage, (4) Blogs, (5) Profiles, (6) Dogear, (7) Activities, and (8) Global Search components. NOTE: the provenance of thi
nvd
CVE-2008-4808MEDIUMCVSS 5.0≤ 2.0v1.0.22008-10-31
CVE-2008-4808 [MEDIUM] CWE-200 CVE-2008-4808: IBM Lotus Connections 2.x before 2.0.1 allows attackers to discover passwords via unspecified vector IBM Lotus Connections 2.x before 2.0.1 allows attackers to discover passwords via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
nvd
CVE-2008-4807LOWCVSS 2.1≤ 2.0v1.0.22008-10-31
CVE-2008-4807 [LOW] CWE-255 CVE-2008-4807: IBM Lotus Connections 2.x before 2.0.1 stores the password for the administrative user in the trace. IBM Lotus Connections 2.x before 2.0.1 stores the password for the administrative user in the trace.log file, which allows local users to obtain sensitive information by reading this file. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
nvd