6.8
CVSSv2

CVE-2010-3892

Published: 12/11/2010 Updated: 10/10/2018
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Session fixation vulnerability in the login form in the administrator interface in IBM OmniFind Enterprise Edition 8.x and 9.x allows remote malicious users to hijack web sessions by replaying a session ID (aka SID) value.

Vulnerable Product Search on Vulmon Subscribe to Product

ibm omnifind 8.0

ibm omnifind 8.4

ibm omnifind 8.5

ibm omnifind 9.0

ibm omnifind 9.1

Exploits

IBM OmniFind suffers from cross site scripting, cross site request forgery, buffer overflow, session fixation and privilege escalation vulnerabilities Various other issues also exist ...