CVE-2014-6130: IBM Notes Traveler

Medium severity, CVSS 5.0. EPSS: 1.9% chance of exploitation in the next 30 days.

The IBM Notes Traveler application before 9.0.1.3 for Android lacks a warning message during selection of an HTTP session, which makes it easier for remote attackers to obtain sensitive information by sniffing the network during a session in which the user had intended to use HTTPS.

Affected products

  • IBM Notes Traveler: up to and including 9.0.1.2

Published 2014-11-04. Last modified 2026-06-17.