5

CVE-2010-3898

IBM OmniFind Enterprise Edition 8.x and 9.x does not properly restrict the cookie path of administrator (aka ESAdmin) cookies, which might allow remote attackers to bypass authentication by leveraging access to other pages on the web site.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
IbmOmnifind Version8.0 Update- Editionenterprise
IbmOmnifind Version8.4 Update- Editionenterprise
IbmOmnifind Version8.5 Update- Editionenterprise
IbmOmnifind Version9.0 Update- Editionenterprise
IbmOmnifind Version9.1 Update- Editionenterprise
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.29% 0.494
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N