Описание
The Top Updates implementation in the Homepage component in IBM Lotus Connections 2.5.x before 2.5.0.2, when "forced SSL" is enabled, uses http for links, which has unspecified impact and remote attack vectors.
Ссылки
- Vendor Advisory
- PatchVendor Advisory
- Vendor Advisory
- Vendor Advisory
- PatchVendor Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:a:ibm:lotus_connections:2.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:lotus_connections:2.5.0.1:*:*:*:*:*:*:*
EPSS
Процентиль: 65%
0.00483
Низкий
7.6 High
CVSS2
Дефекты
NVD-CWE-Other
Связанные уязвимости
github
больше 3 лет назад
The Top Updates implementation in the Homepage component in IBM Lotus Connections 2.5.x before 2.5.0.2, when "forced SSL" is enabled, uses http for links, which has unspecified impact and remote attack vectors.
EPSS
Процентиль: 65%
0.00483
Низкий
7.6 High
CVSS2
Дефекты
NVD-CWE-Other