Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
ibm omnifind 9.1 vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2010-3893
The administrator interface in IBM OmniFind Enterprise Edition 8.x and 9.x does not restrict use of a session ID (aka SID) value to a single IP address, which allows remote malicious users to perform arbitrary administrative actions by leveraging cookie theft, related to a "...
Ibm Omnifind 9.0
Ibm Omnifind 8.0
Ibm Omnifind 8.5
Ibm Omnifind 8.4
Ibm Omnifind 9.1
1 EDB exploit
NA
CVE-2010-3897
ESSearchApplication/palette.do in IBM OmniFind Enterprise Edition 8.x and 9.x includes the administrator password in the HTML source code, which might allow remote malicious users to obtain sensitive information by leveraging read access to this file.
Ibm Omnifind 9.0
Ibm Omnifind 8.0
Ibm Omnifind 8.5
Ibm Omnifind 8.4
Ibm Omnifind 9.1
NA
CVE-2010-3896
The ESSearchApplication directory tree in IBM OmniFind Enterprise Edition 8.x and 9.x does not require authentication, which allows remote malicious users to modify the server configuration via a request to palette.do.
Ibm Omnifind 9.0
Ibm Omnifind 8.0
Ibm Omnifind 8.5
Ibm Omnifind 8.4
Ibm Omnifind 9.1
NA
CVE-2010-3892
Session fixation vulnerability in the login form in the administrator interface in IBM OmniFind Enterprise Edition 8.x and 9.x allows remote malicious users to hijack web sessions by replaying a session ID (aka SID) value.
Ibm Omnifind 9.0
Ibm Omnifind 8.0
Ibm Omnifind 8.5
Ibm Omnifind 8.4
Ibm Omnifind 9.1
NA
CVE-2010-3898
IBM OmniFind Enterprise Edition 8.x and 9.x does not properly restrict the cookie path of administrator (aka ESAdmin) cookies, which might allow remote malicious users to bypass authentication by leveraging access to other pages on the web site.
Ibm Omnifind 9.0
Ibm Omnifind 8.0
Ibm Omnifind 8.5
Ibm Omnifind 8.4
Ibm Omnifind 9.1
NA
CVE-2010-4236
Untrusted search path vulnerability in estaskwrapper in IBM OmniFind Enterprise Edition prior to 9.1 allows local users to gain privileges via an ES_LIBRARY_PATH environment variable and a modified PATH environment variable, which is used during execution of the estasklight progr...
Ibm Omnifind 8.0
Ibm Omnifind 6.1
Ibm Omnifind 8.5
Ibm Omnifind 8.4
Ibm Omnifind
1 EDB exploit
NA
CVE-2010-3895
esRunCommand in IBM OmniFind Enterprise Edition prior to 9.1 allows local users to gain privileges by specifying an arbitrary command name as the first argument.
Ibm Omnifind 8.0
Ibm Omnifind 8.5
Ibm Omnifind 8.4
Ibm Omnifind
1 EDB exploit
NA
CVE-2010-3890
Cross-site scripting (XSS) vulnerability in IBM OmniFind Enterprise Edition prior to 9.1 allows remote malicious users to inject arbitrary web script or HTML via the command parameter to the administration interface, as demonstrated by the command parameter to ESAdmin/collection....
Ibm Omnifind 8.0
Ibm Omnifind 8.5
Ibm Omnifind 8.4
Ibm Omnifind
NA
CVE-2010-3891
Cross-site request forgery (CSRF) vulnerability in ESAdmin/security.do in the administrator interface in IBM OmniFind Enterprise Edition prior to 9.1 allows remote malicious users to hijack the authentication of administrators for requests that add an administrative user via a sa...
Ibm Omnifind 8.0
Ibm Omnifind 8.5
Ibm Omnifind 8.4
Ibm Omnifind
1 EDB exploit
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
type confusion
IMAP
CVE-2024-36103
CVE-2024-28995
CVE-2024-37325
CVE-2024-30078
CVE-2024-30082
SQL injection
CVE-2024-30052
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started