Vulnerabilities > CVE-2010-3899 - Resource Management Errors vulnerability in IBM Omnifind 8.0/9.0
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
IBM OmniFind Enterprise Edition 8.x and 9.x performs web crawls with an unlimited recursion depth, which allows remote web servers to cause a denial of service (infinite loop) via a crafted series of documents.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 2 |
Common Weakness Enumeration (CWE)
Exploit-Db
description | IBM OmniFind Crawler Denial of Service Vulnerability. CVE-2010-3899. Dos exploits for multiple platform |
file | exploits/multiple/dos/15476.php |
id | EDB-ID:15476 |
last seen | 2016-02-01 |
modified | 2010-11-09 |
platform | multiple |
port | |
published | 2010-11-09 |
reporter | Fatih Kilic |
source | https://www.exploit-db.com/download/15476/ |
title | IBM OmniFind Crawler Denial of Service Vulnerability |
type | dos |
Packetstorm
data source | https://packetstormsecurity.com/files/download/95687/ibmomnifind-xssescalate.txt |
id | PACKETSTORM:95687 |
last seen | 2016-12-05 |
published | 2010-11-10 |
reporter | Fatih Kilic |
source | https://packetstormsecurity.com/files/95687/IBM-OmniFind-Cross-Site-Scripting-Privilege-Escalation.html |
title | IBM OmniFind Cross Site Scripting / Privilege Escalation |
Seebug
bulletinFamily | exploit |
description | No description provided by source. |
id | SSV:70181 |
last seen | 2017-11-19 |
modified | 2014-07-01 |
published | 2014-07-01 |
reporter | Root |
source | https://www.seebug.org/vuldb/ssvid-70181 |
title | IBM OmniFind Crawler Denial of Service Vulnerability |
References
- http://security.fatihkilic.de/advisory/fkilic-sa-2010-ibm-omnifind.txt
- http://security.fatihkilic.de/advisory/fkilic-sa-2010-ibm-omnifind.txt
- http://www.exploit-db.com/exploits/15476
- http://www.exploit-db.com/exploits/15476
- http://www.osvdb.org/69078
- http://www.osvdb.org/69078
- http://www.securityfocus.com/archive/1/514688/100/0/threaded
- http://www.securityfocus.com/archive/1/514688/100/0/threaded
- http://www.securityfocus.com/bid/44740
- http://www.securityfocus.com/bid/44740
- http://www.vupen.com/english/advisories/2010/2933
- http://www.vupen.com/english/advisories/2010/2933