← Back

CVE-2010-4595

nvd nist
Published: Dec 22, 2010Modified: Apr 29, 2026

JSON object

Loading...
5.0
Vector
AV:N/AC:L/Au:N/C:N/I:P/A:N
Exploitability: 10.0 / Impact: 2.9
Source: NVD

Description

The Connection Manager in IBM Lotus Mobile Connect before 6.1.4 disables the http.device.stanza blacklisting functionality for HTTP Access Services (HTTP-AS), which allows remote attackers to bypass intended access restrictions via an HTTP request that contains a disallowed User-Agent header.

Affected (4)

1 product
Lotus Mobile Connect
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Ibm
Up to 6.1.3
Version 6.1.1.1
Version 6.1.1
Version 6.1.2

Related CWEs

Timeline

No history available yet.