Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-54h7-8928-76p5

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The Connection Manager in IBM Lotus Mobile Connect (LMC) before 6.1.4, when HTTP Access Services (HTTP-AS) is enabled, does not delete LTPA tokens in response to use of the iNotes Logoff button, which might allow physically proximate attackers to obtain access via an unattended client, related to a cookie domain mismatch.

The Connection Manager in IBM Lotus Mobile Connect (LMC) before 6.1.4, when HTTP Access Services (HTTP-AS) is enabled, does not delete LTPA tokens in response to use of the iNotes Logoff button, which might allow physically proximate attackers to obtain access via an unattended client, related to a cookie domain mismatch.

EPSS

Процентиль: 17%
0.00053
Низкий

Дефекты

CWE-287

Связанные уязвимости

nvd
около 15 лет назад

The Connection Manager in IBM Lotus Mobile Connect (LMC) before 6.1.4, when HTTP Access Services (HTTP-AS) is enabled, does not delete LTPA tokens in response to use of the iNotes Logoff button, which might allow physically proximate attackers to obtain access via an unattended client, related to a cookie domain mismatch.

EPSS

Процентиль: 17%
0.00053
Низкий

Дефекты

CWE-287