6.9
CVSSv2

CVE-2010-4236

Published: 12/11/2010 Updated: 10/10/2018
CVSS v2 Base Score: 6.9 | Impact Score: 10 | Exploitability Score: 3.4
VMScore: 695
Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Untrusted search path vulnerability in estaskwrapper in IBM OmniFind Enterprise Edition prior to 9.1 allows local users to gain privileges via an ES_LIBRARY_PATH environment variable and a modified PATH environment variable, which is used during execution of the estasklight program, a different vulnerability than CVE-2010-3895.

Vulnerable Product Search on Vulmon Subscribe to Product

ibm omnifind 8.0

ibm omnifind 8.5

ibm omnifind

ibm omnifind 8.4

ibm omnifind 6.1

Exploits

* Privilege escalation in two applications (CVE-2010-3895) Root SUID bits are set for the applications »esRunCommand« and »estaskwrapper« ------------------------------------------------------------------------- -rwsr-xr-x 1 root users /opt/IBM/es/bin/esRunCommand -rwsr-xr-x 1 root users /opt/IBM/es/bin/estaskwrapper ------------ ...