The Connection Manager in IBM Lotus Mobile Connect before 6.1.4 does not properly maintain a certain reference count, which allows remote authenticated users to cause a denial of service (IP address exhaustion) by making invalid attempts to establish sessions with the same VPN ID from multiple devices.
AV:N/AC:L/Au:S/C:N/I:N/A:P
This vulnerability has a 1.13% probability of being exploited in the next 30 days, ranking higher than 65% of all scored CVEs.