PT-2010-5150 · Ibm · Ibm Omnifind Enterprise Edition

Publicado

2010-11-12

·

Atualizado

2018-10-10

·

CVE-2010-3896

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions IBM OmniFind Enterprise Edition versions 8.x through 9.x
Description The issue concerns the ESSearchApplication directory tree, which does not require authentication. This allows remote attackers to modify the server configuration by sending a request to the "palette.do" endpoint.
Recommendations For IBM OmniFind Enterprise Edition versions 8.x through 9.x, consider restricting access to the ESSearchApplication directory tree until a fix is available. As a temporary workaround, limit modifications to the server configuration to authorized personnel only.

Exploit

Correção

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2010-3896

Produtos afetados

Ibm Omnifind Enterprise Edition