Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The Connection Manager in IBM Lotus Mobile Connect (LMC) before 6.1.4, when HTTP Access Services (HTTP-AS) is enabled, does not delete LTPA tokens in response to use of the iNotes Logoff button, which might allow physically proximate attackers to obtain access via an unattended client, related to a cookie domain mismatch.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
IBM Lotus Mobile Connect LTPA令牌客户端访问漏洞
Vulnerability Description
IBM Lotus Mobile Connect是一款通信软件平台,可为企业提供一个移动虚拟私人网络。 IBM Lotus Mobile Connect(LMC) 6.1.4之前版本中的Connection Manager在启用HTTP Access Services(HTTP-AS)时,没有删除响应(使用iNotes Logoff按键所产生)中的LTPA令牌。附近攻击者可以借助无人值守的客户端获得访问。
CVSS Information
N/A
Vulnerability Type
N/A