MEDIUM
The Connection Manager in IBM Lotus Mobile Connect before 6.1.4 disables the http.device.stanza blacklisting functionality for HTTP Access Services (HTTP-AS), which allows remote attackers to bypass intended access restrictions via an HTTP request that contains a disallowed User-Agent header
Published Dec 22, 2010
5.0
MEDIUMCVSS 2.0
EPSS 1.26%
Description
Affected products
Remediation
Metrics
References (2)
Change history (0)
No recorded changes yet.