CVE Vulnerabilities

CVE-2010-4236

Published: Nov 12, 2010 | Modified: Oct 10, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.9 MEDIUM
AV:L/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

Untrusted search path vulnerability in estaskwrapper in IBM OmniFind Enterprise Edition before 9.1 allows local users to gain privileges via an ES_LIBRARY_PATH environment variable and a modified PATH environment variable, which is used during execution of the estasklight program, a different vulnerability than CVE-2010-3895.

Affected Software

Name Vendor Start Version End Version
Omnifind Ibm * 9.0 (including)
Omnifind Ibm 6.1 (including) 6.1 (including)
Omnifind Ibm 8.0 (including) 8.0 (including)
Omnifind Ibm 8.4 (including) 8.4 (including)
Omnifind Ibm 8.5 (including) 8.5 (including)

References