Session Impersonation in IBM OmniFind Enterprise Edition
CVE-2010-3893
Currently unrated
What is CVE-2010-3893?
The administrative interface of IBM OmniFind Enterprise Edition versions 8.x and 9.x lacks proper session ID (SID) restrictions, allowing attackers to exploit this flaw. By stealing session cookies, an unauthorized user can impersonate an admin and execute arbitrary administrative actions. This vulnerability poses a significant risk, as it can be leveraged for unauthorized data access and control over the affected system.