CVE-2010-3896

IBM OmniFind Enterprise Edition 8.x/9.x - Unauthenticated Server Configuration Modification

Title source: llm
STIX 2.1

Description

The ESSearchApplication directory tree in IBM OmniFind Enterprise Edition 8.x and 9.x does not require authentication, which allows remote attackers to modify the server configuration via a request to palette.do.

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/514688/100/0/threaded
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/44740
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2010/2933

Scores

EPSS 0.0163
EPSS Percentile 73.2%

Details

CWE
CWE-287
Status published
Products (5)
ibm/omnifind 8.0
ibm/omnifind 8.4
ibm/omnifind 8.5
ibm/omnifind 9.0
ibm/omnifind 9.1
Published Nov 12, 2010
Tracked Since Feb 18, 2026