CVE Vulnerabilities

CVE-2010-3893

Published: Nov 12, 2010 | Modified: Oct 10, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

The administrator interface in IBM OmniFind Enterprise Edition 8.x and 9.x does not restrict use of a session ID (aka SID) value to a single IP address, which allows remote attackers to perform arbitrary administrative actions by leveraging cookie theft, related to a session impersonation issue.

Affected Software

Name Vendor Start Version End Version
Omnifind Ibm 8.0 (including) 8.0 (including)
Omnifind Ibm 8.4 (including) 8.4 (including)
Omnifind Ibm 8.5 (including) 8.5 (including)
Omnifind Ibm 9.0 (including) 9.0 (including)
Omnifind Ibm 9.1 (including) 9.1 (including)

References