Session Fixation Vulnerability in IBM OmniFind Enterprise Edition
CVE-2010-3892

Currently unrated

Key Information:

Vendor
IBM
Status
Vendor
CVE Published:
12 November 2010

Summary

A session fixation vulnerability exists in the administrator interface login form of IBM OmniFind Enterprise Edition versions 8.x and 9.x. This security flaw enables remote attackers to exploit a replayable session ID (SID) value, which can lead to unauthorized session hijacking. If successfully executed, this allows attackers to impersonate valid users, potentially jeopardizing sensitive information and system integrity.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.