5

CVE-2010-3897

ESSearchApplication/palette.do in IBM OmniFind Enterprise Edition 8.x and 9.x includes the administrator password in the HTML source code, which might allow remote attackers to obtain sensitive information by leveraging read access to this file.

Data is provided by the National Vulnerability Database (NVD)
IbmOmnifind Version8.0 Update- Editionenterprise
IbmOmnifind Version8.4 Update- Editionenterprise
IbmOmnifind Version8.5 Update- Editionenterprise
IbmOmnifind Version9.0 Update- Editionenterprise
IbmOmnifind Version9.1 Update- Editionenterprise
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.29% 0.491
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N