9.3
CVSSv2

CVE-2010-3894

Published: 12/11/2010 Updated: 10/10/2018
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 935
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Stack-based buffer overflow in the Java_com_ibm_es_oss_CryptionNative_ESEncrypt function in /opt/IBM/es/lib/libffq.cryptionjni.so in the login form in the administration interface in IBM OmniFind Enterprise Edition prior to 8.5 FP6 allows remote malicious users to execute arbitrary code via a long password.

Vulnerable Product Search on Vulmon Subscribe to Product

ibm omnifind 6.1

ibm omnifind 8.4

ibm omnifind 8.0

ibm omnifind

Exploits

* Remote buffer overflow (CVE-2010-3894) The administration interface has a login form with an username- and a passwordfield Entering a valid username (default value is »esadmin«) and a very long string into the password field a buffer overflow is triggered The function Java_com_ibm_es_oss_CryptionNative_ESEncrypt() defined in the file /opt/I ...
IBM OmniFind suffers from cross site scripting, cross site request forgery, buffer overflow, session fixation and privilege escalation vulnerabilities Various other issues also exist ...