CVE-2010-3898

IBM OmniFind Enterprise Edition 8.x and 9.x does not properly restrict the cookie path of administrator (aka ESAdmin) cookies, which might allow remote attackers to bypass authentication by leveraging access to other pages on the web site.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ibm:omnifind:8.0:-:enterprise:*:*:*:*:*
cpe:2.3:a:ibm:omnifind:8.4:-:enterprise:*:*:*:*:*
cpe:2.3:a:ibm:omnifind:8.5:-:enterprise:*:*:*:*:*
cpe:2.3:a:ibm:omnifind:9.0:-:enterprise:*:*:*:*:*
cpe:2.3:a:ibm:omnifind:9.1:-:enterprise:*:*:*:*:*

History

No history.

Information

Published : 2010-11-12 22:00

Updated : 2024-02-04 17:54


NVD link : CVE-2010-3898

Mitre link : CVE-2010-3898

CVE.ORG link : CVE-2010-3898


JSON object : View

Products Affected

ibm

  • omnifind
CWE
CWE-264

Permissions, Privileges, and Access Controls