Information Disclosure Vulnerability in IBM OmniFind Enterprise Edition
CVE-2010-3897

Currently unrated

Key Information:

Vendor
IBM
Status
Vendor
CVE Published:
12 November 2010

Summary

A vulnerability in IBM OmniFind Enterprise Edition versions 8.x and 9.x allows attackers to access sensitive information by exploiting the inclusion of the administrator password in the HTML source code of the ESSearchApplication/palette.do file. By gaining read access to this file, remote attackers can potentially retrieve the administrator password, which poses a significant security risk.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.