CVE-2010-3898

IBM OmniFind Enterprise Edition 8.x and 9.x does not properly restrict the cookie path of administrator (aka ESAdmin) cookies, which might allow remote attackers to bypass authentication by leveraging access to other pages on the web site.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ibm:omnifind:9.0:-:enterprise:*:*:*:*:*
cpe:2.3:a:ibm:omnifind:9.1:-:enterprise:*:*:*:*:*
cpe:2.3:a:ibm:omnifind:8.4:-:enterprise:*:*:*:*:*
cpe:2.3:a:ibm:omnifind:8.5:-:enterprise:*:*:*:*:*
cpe:2.3:a:ibm:omnifind:8.0:-:enterprise:*:*:*:*:*

Information

Published : 2010-11-12 14:00

Updated : 2018-10-10 13:06


NVD link : CVE-2010-3898

Mitre link : CVE-2010-3898


JSON object : View

CWE
CWE-264

Permissions, Privileges, and Access Controls

Advertisement

dedicated server usa

Products Affected

ibm

  • omnifind