7.2
CVSSv2

CVE-2010-3895

Published: 12/11/2010 Updated: 10/10/2018
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 725
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

esRunCommand in IBM OmniFind Enterprise Edition prior to 9.1 allows local users to gain privileges by specifying an arbitrary command name as the first argument.

Vulnerable Product Search on Vulmon Subscribe to Product

ibm omnifind 8.5

ibm omnifind

ibm omnifind 8.0

ibm omnifind 8.4

Exploits

* Privilege escalation in two applications (CVE-2010-3895) Root SUID bits are set for the applications »esRunCommand« and »estaskwrapper« ------------------------------------------------------------------------- -rwsr-xr-x 1 root users /opt/IBM/es/bin/esRunCommand -rwsr-xr-x 1 root users /opt/IBM/es/bin/estaskwrapper ------------ ...
IBM OmniFind suffers from cross site scripting, cross site request forgery, buffer overflow, session fixation and privilege escalation vulnerabilities Various other issues also exist ...