The Top Updates implementation in the Homepage component in IBM Lotus Connections 2.5.x before 2.5.0.2, when forced SSL is enabled, uses http for links, which has unspecified impact and remote attack vectors.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Lotus_connections | Ibm | 2.5.0 (including) | 2.5.0 (including) |
Lotus_connections | Ibm | 2.5.0.1 (including) | 2.5.0.1 (including) |