CVE-2010-2278
Summary
| CVE | CVE-2010-2278 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2010-06-15 14:30:01 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | The bookmarklet pop-up in the Bookmarks component in IBM Lotus Connections 2.5.x before 2.5.0.2 does not properly follow the "force SSL" setting, which might make it easier for remote attackers to obtain the cleartext of network communication by sniffing the network, or spoof arbitrary servers via a man-in-the-middle attack. |
Risk And Classification
Primary CVSS: v2.0 4 from [email protected]
AV:N/AC:H/Au:N/C:P/I:P/A:N
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
HighAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
NoneAV:N/AC:H/Au:N/C:P/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ibm | Lotus Connections | 2.5.0 | All | All | All |
| Application | Ibm | Lotus Connections | 2.5.0.1 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM Fix List and installation instructions for Lotus Connections 2.5.0 Fix Pack 2 (2.5.0.2) - United States | af854a3a-2127-422b-91ae-364da2661108 | www-01.ibm.com | Patch, Vendor Advisory |
| IBM LO47496: THE BOOKMARKLET POPUP IS STILL USING HTTP WHEN FORCE SSL IS ENABLED, THIS IS THE FIX FOR THIS ISSUE | af854a3a-2127-422b-91ae-364da2661108 | www-1.ibm.com | |
| IBM LO47610: THE BOOKMARKLET POPUP IS STILL USING HTTP WHEN FORCE SSL IS ENABLED, THIS IS THE FIX FOR THIS ISSUE | af854a3a-2127-422b-91ae-364da2661108 | www-1.ibm.com | |
| IBM LO47501: THE BOOKMARKLET POPUP IS STILL USING HTTP WHEN FORCE SSL IS ENABLED, THIS IS THE FIX FOR THIS ISSUE | af854a3a-2127-422b-91ae-364da2661108 | www-1.ibm.com | |
| IBM LO47642: THE BOOKMARKLET POPUP IS STILL USING HTTP WHEN FORCE SSL IS ENABLED, THIS IS THE FIX FOR THIS ISSUE | af854a3a-2127-422b-91ae-364da2661108 | www-1.ibm.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Vendor Advisory |
| IBM LO47669: THE BOOKMARKLET POPUP IS STILL USING HTTP WHEN FORCE SSL IS ENABLED, THIS IS THE FIX FOR THIS ISSUE | af854a3a-2127-422b-91ae-364da2661108 | www-1.ibm.com | |
| IBM Lotus Connections Multiple Vulnerabilities - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| IBM LO47429: THE BOOKMARKLET POPUP IS STILL USING HTTP WHEN FORCE SSL IS ENABLED, THIS IS THE FIX FOR THIS ISSUE. | af854a3a-2127-422b-91ae-364da2661108 | www-1.ibm.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.