5
CVSSv2

CVE-2010-3897

Published: 12/11/2010 Updated: 10/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

ESSearchApplication/palette.do in IBM OmniFind Enterprise Edition 8.x and 9.x includes the administrator password in the HTML source code, which might allow remote malicious users to obtain sensitive information by leveraging read access to this file.

Vulnerable Product Search on Vulmon Subscribe to Product

ibm omnifind 9.0

ibm omnifind 9.1

ibm omnifind 8.4

ibm omnifind 8.5

ibm omnifind 8.0

Exploits

IBM OmniFind suffers from cross site scripting, cross site request forgery, buffer overflow, session fixation and privilege escalation vulnerabilities Various other issues also exist ...