IBM Lotus Mobile Connect contains a flaw related to the Connection Manager. When HTTP Access Services (HTTP-AS) is enabled, the program does not properly delete LTPA tokens in response to the use of the iNotes Logoff button. This may allow physically present attackers to obtain access via an unattended client.
Classification
Location:
Physical Access Required
Attack Type:
Other
Impact:
Loss of Confidentiality,
Loss of Integrity
Solution:
Upgrade
Exploit:
Exploit Public
Disclosure:
Vendor Verified
OSVDB:
Web Related
Solution
Upgrade to version 6.1.4 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.