7.5
CVSSv2

CVE-2010-3893

Published: 12/11/2010 Updated: 10/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The administrator interface in IBM OmniFind Enterprise Edition 8.x and 9.x does not restrict use of a session ID (aka SID) value to a single IP address, which allows remote malicious users to perform arbitrary administrative actions by leveraging cookie theft, related to a "session impersonation" issue.

Vulnerable Product Search on Vulmon Subscribe to Product

ibm omnifind 8.0

ibm omnifind 8.4

ibm omnifind 9.1

ibm omnifind 8.5

ibm omnifind 9.0

Exploits

source: wwwsecurityfocuscom/bid/44940/info IBM OmniFind is prone to a cross-site scripting vulnerability because it fails to sufficiently sanitize user-supplied data An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site This may allow the attacker ...
IBM OmniFind suffers from cross site scripting, cross site request forgery, buffer overflow, session fixation and privilege escalation vulnerabilities Various other issues also exist ...