First published: Mon Jun 14 2010(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in IBM Lotus Connections 2.5.x before 2.5.0.2 allow remote attackers to inject arbitrary web script or HTML via the (1) create or (2) edit form in the Communities component, the (3) verbiage field in the Bookmarks component, or (4) unspecified vectors related to the Mobile Blogs component.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Connections | =2.5.0.1 | |
IBM Connections | =2.5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-2277 has been classified with a medium severity rating due to its potential for cross-site scripting attacks.
To fix CVE-2010-2277, update IBM Lotus Connections to version 2.5.0.2 or later.
CVE-2010-2277 affects the Communities and Bookmarks components in IBM Lotus Connections.
Yes, CVE-2010-2277 can be exploited remotely by injecting arbitrary web scripts or HTML.
IBM Lotus Connections versions 2.5.0.1 and 2.5.0 are vulnerable to CVE-2010-2277.