Cross-Site Request Forgery in IBM OmniFind Enterprise Edition
CVE-2010-3891

Currently unrated

Key Information:

Vendor
IBM
Status
Vendor
CVE Published:
12 November 2010

Summary

A cross-site request forgery (CSRF) vulnerability exists in the administrator interface of IBM OmniFind Enterprise Edition, specifically within the ESAdmin/security.do component. This flaw allows remote attackers to exploit the trust between an authenticated administrator and the web application, enabling them to hijack the administrator's session. An attacker can perform user-relevant actions such as adding new administrative users through the saveNewUser functionality, potentially compromising the entire system's integrity and security.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.