The Connection Manager in IBM Lotus Mobile Connect before 6.1.4 does not properly maintain a certain reference count, which allows remote authenticated users to cause a denial of service (IP address exhaustion) by making invalid attempts to establish sessions with the same VPN ID from multiple devices.
Weaknesses in this category are related to improper management of system resources.
Link | Tags |
---|---|
http://secunia.com/advisories/42703 | third party advisory |
http://www-01.ibm.com/support/docview.wss?uid=swg1IZ75012 | vendor advisory |
http://www-01.ibm.com/support/docview.wss?uid=swg27020327 |