CVE-2011-4465
- EPSS 0.23%
- Published 19.11.2011 03:58:55
- Last modified 11.04.2025 00:51:21
Cross-site scripting (XSS) vulnerability in IBM Lotus Mobile Connect (LMC) 6.1.4 allows remote attackers to inject arbitrary web script or HTML via vectors related to a hidden redirect URL.
- EPSS 0.14%
- Published 22.12.2010 21:00:20
- Last modified 11.04.2025 00:51:21
The Connection Manager in IBM Lotus Mobile Connect before 6.1.4 disables the http.device.stanza blacklisting functionality for HTTP Access Services (HTTP-AS), which allows remote attackers to bypass intended access restrictions via an HTTP request th...
CVE-2010-4590
- EPSS 0.26%
- Published 22.12.2010 21:00:19
- Last modified 11.04.2025 00:51:21
Cross-site scripting (XSS) vulnerability in HTTP Access Services (HTTP-AS) in the Connection Manager in IBM Lotus Mobile Connect (LMC) before 6.1.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2010-4591
- EPSS 0.05%
- Published 22.12.2010 21:00:19
- Last modified 11.04.2025 00:51:21
The Connection Manager in IBM Lotus Mobile Connect (LMC) before 6.1.4, when HTTP Access Services (HTTP-AS) is enabled, does not delete LTPA tokens in response to use of the iNotes Logoff button, which might allow physically proximate attackers to obt...
CVE-2010-4592
- EPSS 0.6%
- Published 22.12.2010 21:00:19
- Last modified 11.04.2025 00:51:21
The Mobile Network Connections functionality in the Connection Manager in IBM Lotus Mobile Connect before 6.1.4, when HTTP Access Services (HTTP-AS) is enabled, does not properly handle failed attempts at establishing HTTP-TCP sessions, which allows ...
- EPSS 0.41%
- Published 22.12.2010 21:00:19
- Last modified 11.04.2025 00:51:21
The Connection Manager in IBM Lotus Mobile Connect before 6.1.4 does not properly maintain a certain reference count, which allows remote authenticated users to cause a denial of service (IP address exhaustion) by making invalid attempts to establish...
CVE-2010-4594
- EPSS 0.54%
- Published 22.12.2010 21:00:19
- Last modified 11.04.2025 00:51:21
The Connection Manager in IBM Lotus Mobile Connect before 6.1.4, when HTTP Access Services (HTTP-AS) is enabled, does not properly process TCP connection requests, which allows remote attackers to cause a denial of service (memory consumption and HTT...