Denial of Service Vulnerability in IBM OmniFind Enterprise Edition
CVE-2010-3899

Currently unrated

Key Information:

Vendor
IBM
Status
Vendor
CVE Published:
12 November 2010

Summary

IBM OmniFind Enterprise Edition versions 8.x and 9.x are affected by a vulnerability that allows remote web servers to exploit the web crawling feature. The crawler's unlimited recursion depth may lead to a denial of service situation, causing an infinite loop when a specially crafted series of documents are processed. This can render the service inoperable, impacting availability and service continuity.

References

EPSS Score

11% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.