Vulnerabilities > CVE-2010-3892 - Multiple vulnerability in RETIRED: IBM OmniFind

047910
CVSS 6.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
ibm

Summary

Session fixation vulnerability in the login form in the administrator interface in IBM OmniFind Enterprise Edition 8.x and 9.x allows remote attackers to hijack web sessions by replaying a session ID (aka SID) value. Per: http://cwe.mitre.org/data/definitions/384.html 'CWE-384: Session Fixation'

Vulnerable Configurations

Part Description Count
Application
Ibm
5

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/95687/ibmomnifind-xssescalate.txt
idPACKETSTORM:95687
last seen2016-12-05
published2010-11-10
reporterFatih Kilic
sourcehttps://packetstormsecurity.com/files/95687/IBM-OmniFind-Cross-Site-Scripting-Privilege-Escalation.html
titleIBM OmniFind Cross Site Scripting / Privilege Escalation