Skip to main content

Vendor/product archive

ibm / lotus_connections CVEs

Beta · best-effort

14 CVEs tagged to ibm / lotus_connections1 Critical, 2 High, 10 Medium, 1 Low, 0 Unrated.

CVE-2013-0503

Published Apr 23, 2013

Cross-site scripting (XSS) vulnerability in the Bookmarks component in IBM Lotus Connections before 4.0 CR3 allows remote attackers to inject arbitrary web script or HTML via unsp…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-1030

Published Feb 14, 2011

Cross-site scripting (XSS) vulnerability in the Wikis component in IBM Lotus Connections 3.0 allows remote attackers to inject arbitrary web script or HTML via vectors related to…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-2280

Published Jun 15, 2010

Open redirect vulnerability in the Mobile component in IBM Lotus Connections 2.5.x before 2.5.0.2 allows remote attackers to redirect users to arbitrary web sites and conduct phis…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-2279

Published Jun 15, 2010

The Top Updates implementation in the Homepage component in IBM Lotus Connections 2.5.x before 2.5.0.2, when "forced SSL" is enabled, uses http for links, which has unspecified im…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2010-2278

Published Jun 15, 2010

The bookmarklet pop-up in the Bookmarks component in IBM Lotus Connections 2.5.x before 2.5.0.2 does not properly follow the "force SSL" setting, which might make it easier for re…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-2277

Published Jun 15, 2010

Multiple cross-site scripting (XSS) vulnerabilities in IBM Lotus Connections 2.5.x before 2.5.0.2 allow remote attackers to inject arbitrary web script or HTML via the (1) create…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-3816

Published Oct 28, 2009

Multiple cross-site scripting (XSS) vulnerabilities in Activities pages in the Mobile subsystem in IBM Lotus Connections 2.5.0.0 allow remote attackers to inject arbitrary web scr…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-3469

Published Sep 29, 2009

Cross-site scripting (XSS) vulnerability in profiles/html/simpleSearch.do in IBM Lotus Connections 2.0.1 allows remote attackers to inject arbitrary web script or HTML via the nam…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-4809

Published Oct 31, 2008

Multiple unspecified vulnerabilities in the Profiles search pages in IBM Lotus Connections 2.x before 2.0.1 have unknown impact and attack vectors related to "Active" content. NO…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-4808

Published Oct 31, 2008

IBM Lotus Connections 2.x before 2.0.1 allows attackers to discover passwords via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtain…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-4807

Published Oct 31, 2008

IBM Lotus Connections 2.x before 2.0.1 stores the password for the administrative user in the trace.log file, which allows local users to obtain sensitive information by reading t…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2008-4806

Published Oct 31, 2008

Multiple SQL injection vulnerabilities in IBM Lotus Connections 2.x before 2.0.1 allow remote attackers to execute arbitrary SQL commands via the sortField parameter to unspecifie…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-4805

Published Oct 31, 2008

Multiple cross-site scripting (XSS) vulnerabilities in IBM Lotus Connections 2.x before 2.0.1 allow remote attackers to inject arbitrary web script or HTML via (1) the community t…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-14 of 14 CVEsPage 1 of 1