Buffer Overflow in IBM OmniFind Enterprise Edition Administration Interface
CVE-2010-3894

Currently unrated

Key Information:

Vendor

IBM

Status
Vendor
CVE Published:
12 November 2010

What is CVE-2010-3894?

A stack-based buffer overflow vulnerability exists in the Java_com_ibm_es_oss_CryptionNative_ESEncrypt function within the IBM OmniFind Enterprise Edition's administration interface. Specifically, this flaw is present in the library 'libffq.cryptionjni.so', which can allow remote attackers to execute arbitrary code. The vulnerability is exploited by sending a specially crafted long password to the login form, highlighting the importance of robust input validation in security protocols. Organizations using affected versions should apply updates promptly to mitigate risks associated with this vulnerability.

References

EPSS Score

14% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.