Vulnerability Details CVE-2010-4595
The Connection Manager in IBM Lotus Mobile Connect before 6.1.4 disables the http.device.stanza blacklisting functionality for HTTP Access Services (HTTP-AS), which allows remote attackers to bypass intended access restrictions via an HTTP request that contains a disallowed User-Agent header.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 35.7%
CVSS Severity
CVSS v2 Score 5.0
Products affected by CVE-2010-4595
-
cpe:2.3:a:ibm:lotus_mobile_connect:6.1
-
cpe:2.3:a:ibm:lotus_mobile_connect:6.1.1
-
cpe:2.3:a:ibm:lotus_mobile_connect:6.1.1.1
-
cpe:2.3:a:ibm:lotus_mobile_connect:6.1.2
-
cpe:2.3:a:ibm:lotus_mobile_connect:6.1.3