PT-2010-5150 · Ibm · Ibm Omnifind Enterprise Edition

Published

2010-11-12

·

Updated

2018-10-10

·

CVE-2010-3896

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions IBM OmniFind Enterprise Edition versions 8.x through 9.x
Description The issue concerns the ESSearchApplication directory tree, which does not require authentication. This allows remote attackers to modify the server configuration by sending a request to the "palette.do" endpoint.
Recommendations For IBM OmniFind Enterprise Edition versions 8.x through 9.x, consider restricting access to the ESSearchApplication directory tree until a fix is available. As a temporary workaround, limit modifications to the server configuration to authorized personnel only.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2010-3896

Affected Products

Ibm Omnifind Enterprise Edition