First published: Tue Nov 04 2014(Updated: )
The IBM Notes Traveler application before 9.0.1.3 for Android lacks a warning message during selection of an HTTP session, which makes it easier for remote attackers to obtain sensitive information by sniffing the network during a session in which the user had intended to use HTTPS.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Notes Traveler | <=9.0.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-6130 is classified as a medium severity vulnerability due to its potential to expose sensitive information.
To fix CVE-2014-6130, upgrade the IBM Notes Traveler application to version 9.0.1.3 or later.
CVE-2014-6130 can allow remote attackers to intercept sensitive information if users mistakenly use an unsecured HTTP connection instead of HTTPS.
CVE-2014-6130 affects users of the IBM Notes Traveler application on Android devices prior to version 9.0.1.3.
As a workaround for CVE-2014-6130, users should ensure they only connect to networks that provide secure connections.