7.5
CVSSv2

CVE-2010-3896

Published: 12/11/2010 Updated: 10/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The ESSearchApplication directory tree in IBM OmniFind Enterprise Edition 8.x and 9.x does not require authentication, which allows remote malicious users to modify the server configuration via a request to palette.do.

Vulnerable Product Search on Vulmon Subscribe to Product

ibm omnifind 8.0

ibm omnifind 9.1

ibm omnifind 8.4

ibm omnifind 8.5

ibm omnifind 9.0

Exploits

IBM OmniFind suffers from cross site scripting, cross site request forgery, buffer overflow, session fixation and privilege escalation vulnerabilities Various other issues also exist ...