First published: Tue Jun 15 2010(Updated: )
The bookmarklet pop-up in the Bookmarks component in IBM Lotus Connections 2.5.x before 2.5.0.2 does not properly follow the "force SSL" setting, which might make it easier for remote attackers to obtain the cleartext of network communication by sniffing the network, or spoof arbitrary servers via a man-in-the-middle attack.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Connections | =2.5.0 | |
IBM Connections | =2.5.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-2278 is classified as a moderate risk vulnerability due to its potential for exposing cleartext data during network communication.
CVE-2010-2278 affects IBM Lotus Connections versions 2.5.0 and 2.5.0.1.
To mitigate CVE-2010-2278, you should upgrade to IBM Lotus Connections version 2.5.0.2 or later.
CVE-2010-2278 can allow remote attackers to intercept cleartext network communication, increasing the risk of data exposure.
Currently, there are no specific workarounds available for CVE-2010-2278, making updates the best solution.