CVE-2010-4236

IBM OmniFind EE <9.1 - Privilege Escalation

Title source: llm
STIX 2.1

Description

Untrusted search path vulnerability in estaskwrapper in IBM OmniFind Enterprise Edition before 9.1 allows local users to gain privileges via an ES_LIBRARY_PATH environment variable and a modified PATH environment variable, which is used during execution of the estasklight program, a different vulnerability than CVE-2010-3895.

Exploits (1)

exploitdb WORKING POC
by Fatih Kilic · textlocalmultiple
https://www.exploit-db.com/exploits/15475

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/514688/100/0/threaded
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/15475
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/44740
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2010/2933

Scores

EPSS 0.0091
EPSS Percentile 75.8%

Details

Status published
Products (5)
ibm/omnifind 6.1
ibm/omnifind 8.0
ibm/omnifind 8.4
ibm/omnifind 8.5
ibm/omnifind < 9.0
Published Nov 12, 2010
Tracked Since Feb 18, 2026