First published: Tue Jun 15 2010(Updated: )
Open redirect vulnerability in the Mobile component in IBM Lotus Connections 2.5.x before 2.5.0.2 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors, related to "mobile edit actions," aka SPR ASRE83PPVH.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Connections | =2.5.0 | |
IBM Connections | =2.5.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-2280 has a medium severity level due to its potential for phishing attacks.
To fix CVE-2010-2280, upgrade IBM Lotus Connections to version 2.5.0.2 or later.
CVE-2010-2280 is classified as an open redirect vulnerability.
CVE-2010-2280 affects IBM Lotus Connections version 2.5.0.1 and older versions.
Attackers can exploit CVE-2010-2280 to redirect users to arbitrary websites, enabling phishing attempts.