{"api_version":"1","generated_at":"2026-07-23T08:11:53+00:00","cve":"CVE-2010-2278","urls":{"html":"https://cve.report/CVE-2010-2278","api":"https://cve.report/api/cve/CVE-2010-2278.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2010-2278","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2010-2278"},"summary":{"title":"CVE-2010-2278","description":"The bookmarklet pop-up in the Bookmarks component in IBM Lotus Connections 2.5.x before 2.5.0.2 does not properly follow the \"force SSL\" setting, which might make it easier for remote attackers to obtain the cleartext of network communication by sniffing the network, or spoof arbitrary servers via a man-in-the-middle attack.","state":"PUBLISHED","assigner":"mitre","published_at":"2010-06-15 14:30:01","updated_at":"2026-04-29 01:13:23"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4","severity":"","vector":"AV:N/AC:H/Au:N/C:P/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:H/Au:N/C:P/I:P/A:N","baseScore":4,"accessVector":"NETWORK","accessComplexity":"HIGH","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://www-01.ibm.com/support/docview.wss?uid=swg21431472","name":"http://www-01.ibm.com/support/docview.wss?uid=swg21431472","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"IBM Fix List and installation instructions for Lotus Connections 2.5.0 Fix Pack 2 (2.5.0.2) - United States","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://www-1.ibm.com/support/docview.wss?uid=swg1LO47496","name":"http://www-1.ibm.com/support/docview.wss?uid=swg1LO47496","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM LO47496: THE BOOKMARKLET POPUP IS STILL USING HTTP WHEN FORCE SSL IS ENABLED, THIS IS THE FIX FOR THIS ISSUE","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www-1.ibm.com/support/docview.wss?uid=swg1LO47610","name":"http://www-1.ibm.com/support/docview.wss?uid=swg1LO47610","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM LO47610: THE BOOKMARKLET POPUP IS STILL USING HTTP WHEN FORCE SSL IS ENABLED, THIS IS THE FIX FOR THIS ISSUE","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www-1.ibm.com/support/docview.wss?uid=swg1LO47501","name":"http://www-1.ibm.com/support/docview.wss?uid=swg1LO47501","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM LO47501: THE BOOKMARKLET POPUP IS STILL USING HTTP WHEN FORCE SSL IS ENABLED, THIS IS THE FIX FOR THIS ISSUE","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www-1.ibm.com/support/docview.wss?uid=swg1LO47642","name":"http://www-1.ibm.com/support/docview.wss?uid=swg1LO47642","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM LO47642: THE BOOKMARKLET POPUP IS STILL USING HTTP WHEN FORCE SSL IS     ENABLED, THIS IS THE FIX FOR THIS ISSUE","mime":"text/html","httpstatus":"403","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2010/1281","name":"http://www.vupen.com/english/advisories/2010/1281","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"inode/x-empty","httpstatus":"200","archivestatus":"200"},{"url":"http://www-1.ibm.com/support/docview.wss?uid=swg1LO47669","name":"http://www-1.ibm.com/support/docview.wss?uid=swg1LO47669","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM LO47669: THE BOOKMARKLET POPUP IS STILL USING HTTP WHEN FORCE SSL IS ENABLED, THIS IS THE FIX FOR THIS ISSUE","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/40007","name":"http://secunia.com/advisories/40007","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"IBM Lotus Connections Multiple Vulnerabilities - Advisories - Community","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www-1.ibm.com/support/docview.wss?uid=swg1LO47429","name":"http://www-1.ibm.com/support/docview.wss?uid=swg1LO47429","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM LO47429: THE BOOKMARKLET POPUP IS STILL USING HTTP WHEN FORCE SSL IS ENABLED, THIS IS THE FIX FOR THIS ISSUE.","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2010-2278","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2010-2278","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2010","cve_id":"2278","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"lotus_connections","cpe6":"2.5.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"2278","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"lotus_connections","cpe6":"2.5.0.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T02:25:07.604Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"ADV-2010-1281","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2010/1281"},{"name":"LO47496","tags":["vendor-advisory","x_refsource_AIXAPAR","x_transferred"],"url":"http://www-1.ibm.com/support/docview.wss?uid=swg1LO47496"},{"name":"LO47642","tags":["vendor-advisory","x_refsource_AIXAPAR","x_transferred"],"url":"http://www-1.ibm.com/support/docview.wss?uid=swg1LO47642"},{"name":"LO47669","tags":["vendor-advisory","x_refsource_AIXAPAR","x_transferred"],"url":"http://www-1.ibm.com/support/docview.wss?uid=swg1LO47669"},{"name":"LO47610","tags":["vendor-advisory","x_refsource_AIXAPAR","x_transferred"],"url":"http://www-1.ibm.com/support/docview.wss?uid=swg1LO47610"},{"name":"LO47501","tags":["vendor-advisory","x_refsource_AIXAPAR","x_transferred"],"url":"http://www-1.ibm.com/support/docview.wss?uid=swg1LO47501"},{"name":"40007","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/40007"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www-01.ibm.com/support/docview.wss?uid=swg21431472"},{"name":"LO47429","tags":["vendor-advisory","x_refsource_AIXAPAR","x_transferred"],"url":"http://www-1.ibm.com/support/docview.wss?uid=swg1LO47429"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"descriptions":[{"lang":"en","value":"The bookmarklet pop-up in the Bookmarks component in IBM Lotus Connections 2.5.x before 2.5.0.2 does not properly follow the \"force SSL\" setting, which might make it easier for remote attackers to obtain the cleartext of network communication by sniffing the network, or spoof arbitrary servers via a man-in-the-middle attack."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2010-06-14T19:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"ADV-2010-1281","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2010/1281"},{"name":"LO47496","tags":["vendor-advisory","x_refsource_AIXAPAR"],"url":"http://www-1.ibm.com/support/docview.wss?uid=swg1LO47496"},{"name":"LO47642","tags":["vendor-advisory","x_refsource_AIXAPAR"],"url":"http://www-1.ibm.com/support/docview.wss?uid=swg1LO47642"},{"name":"LO47669","tags":["vendor-advisory","x_refsource_AIXAPAR"],"url":"http://www-1.ibm.com/support/docview.wss?uid=swg1LO47669"},{"name":"LO47610","tags":["vendor-advisory","x_refsource_AIXAPAR"],"url":"http://www-1.ibm.com/support/docview.wss?uid=swg1LO47610"},{"name":"LO47501","tags":["vendor-advisory","x_refsource_AIXAPAR"],"url":"http://www-1.ibm.com/support/docview.wss?uid=swg1LO47501"},{"name":"40007","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/40007"},{"tags":["x_refsource_CONFIRM"],"url":"http://www-01.ibm.com/support/docview.wss?uid=swg21431472"},{"name":"LO47429","tags":["vendor-advisory","x_refsource_AIXAPAR"],"url":"http://www-1.ibm.com/support/docview.wss?uid=swg1LO47429"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2010-2278","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The bookmarklet pop-up in the Bookmarks component in IBM Lotus Connections 2.5.x before 2.5.0.2 does not properly follow the \"force SSL\" setting, which might make it easier for remote attackers to obtain the cleartext of network communication by sniffing the network, or spoof arbitrary servers via a man-in-the-middle attack."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"ADV-2010-1281","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2010/1281"},{"name":"LO47496","refsource":"AIXAPAR","url":"http://www-1.ibm.com/support/docview.wss?uid=swg1LO47496"},{"name":"LO47642","refsource":"AIXAPAR","url":"http://www-1.ibm.com/support/docview.wss?uid=swg1LO47642"},{"name":"LO47669","refsource":"AIXAPAR","url":"http://www-1.ibm.com/support/docview.wss?uid=swg1LO47669"},{"name":"LO47610","refsource":"AIXAPAR","url":"http://www-1.ibm.com/support/docview.wss?uid=swg1LO47610"},{"name":"LO47501","refsource":"AIXAPAR","url":"http://www-1.ibm.com/support/docview.wss?uid=swg1LO47501"},{"name":"40007","refsource":"SECUNIA","url":"http://secunia.com/advisories/40007"},{"name":"http://www-01.ibm.com/support/docview.wss?uid=swg21431472","refsource":"CONFIRM","url":"http://www-01.ibm.com/support/docview.wss?uid=swg21431472"},{"name":"LO47429","refsource":"AIXAPAR","url":"http://www-1.ibm.com/support/docview.wss?uid=swg1LO47429"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2010-2278","datePublished":"2010-06-14T19:00:00.000Z","dateReserved":"2010-06-14T00:00:00.000Z","dateUpdated":"2024-09-16T20:16:35.176Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2010-06-15 14:30:01","lastModifiedDate":"2026-04-29 01:13:23","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:H/Au:N/C:P/I:P/A:N","baseScore":4,"accessVector":"NETWORK","accessComplexity":"HIGH","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":4.9,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:lotus_connections:2.5.0:*:*:*:*:*:*:*","matchCriteriaId":"C158C61A-ADC7-410D-93D1-25F594B089B0"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:lotus_connections:2.5.0.1:*:*:*:*:*:*:*","matchCriteriaId":"1F331AFF-4A81-4131-A310-E71B51157EC0"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2010","CveId":"2278","Ordinal":"1","Title":"CVE-2010-2278","CVE":"CVE-2010-2278","Year":"2010"},"notes":[{"CveYear":"2010","CveId":"2278","Ordinal":"1","NoteData":"The bookmarklet pop-up in the Bookmarks component in IBM Lotus Connections 2.5.x before 2.5.0.2 does not properly follow the \"force SSL\" setting, which might make it easier for remote attackers to obtain the cleartext of network communication by sniffing the network, or spoof arbitrary servers via a man-in-the-middle attack.","Type":"Description","Title":"CVE-2010-2278"},{"CveYear":"2010","CveId":"2278","Ordinal":"2","NoteData":"2010-06-14","Type":"Other","Title":"Published"}]}}}