The Top Updates implementation in the Homepage component in IBM Lotus Connections 2.5.x before 2.5.0.2, when "forced SSL" is enabled, uses http for links, which has unspecified impact and remote attack vectors.
Link | Tags |
---|---|
http://www.vupen.com/english/advisories/2010/1281 | vdb entry vendor advisory |
http://secunia.com/advisories/40007 | third party advisory vendor advisory |
http://www-01.ibm.com/support/docview.wss?uid=swg21431472 | patch vendor advisory |
http://www-1.ibm.com/support/docview.wss?uid=swg1LO48325 | vendor advisory |