5
CVSSv2

CVE-2010-3898

Published: 12/11/2010 Updated: 10/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

IBM OmniFind Enterprise Edition 8.x and 9.x does not properly restrict the cookie path of administrator (aka ESAdmin) cookies, which might allow remote malicious users to bypass authentication by leveraging access to other pages on the web site.

Vulnerable Product Search on Vulmon Subscribe to Product

ibm omnifind 9.0

ibm omnifind 9.1

ibm omnifind 8.4

ibm omnifind 8.5

ibm omnifind 8.0

Exploits

IBM OmniFind suffers from cross site scripting, cross site request forgery, buffer overflow, session fixation and privilege escalation vulnerabilities Various other issues also exist ...