The Connection Manager in IBM Lotus Mobile Connect (LMC) before 6.1.4, when HTTP Access Services (HTTP-AS) is enabled, does not delete LTPA tokens in response to use of the iNotes Logoff button, which might allow physically proximate attackers to obtain access via an unattended client, related to a cookie domain mismatch.
2010-12-22T21:00:19.863
2025-04-11T00:51:21.963
Deferred
CVSSv2: 4.4 (MEDIUM)
AV:L/AC:M/Au:N/C:P/I:P/A:P
3.4
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | ibm | lotus_mobile_connect | ≤ 6.1.3 | Yes |
Application | ibm | lotus_mobile_connect | 6.1.1 | Yes |
Application | ibm | lotus_mobile_connect | 6.1.1.1 | Yes |
Application | ibm | lotus_mobile_connect | 6.1.2 | Yes |