Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The Connection Manager in IBM Lotus Mobile Connect before 6.1.4 disables the http.device.stanza blacklisting functionality for HTTP Access Services (HTTP-AS), which allows remote attackers to bypass intended access restrictions via an HTTP request that contains a disallowed User-Agent header.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
IBM Lotus Mobile Connect HTTP请求预设访问限制绕过漏洞
Vulnerability Description
IBM Lotus Mobile Connect是一款通信软件平台,可为企业提供一个移动虚拟私人网络。 IBM Lotus Mobile Connect(LMC) 6.1.4之前版本中的Connection Manager禁用了针对HTTP Access Services (HTTP-AS)的http.device.stanza黑名单功能。远程攻击者可以借助包含不允许User-Agent头的HTTP请求绕过预设的访问限制。
CVSS Information
N/A
Vulnerability Type
N/A