Lucene search

K
cveMitreCVE-2010-3895
HistoryNov 12, 2010 - 10:00 p.m.

CVE-2010-3895

2010-11-1222:00:02
CWE-264
mitre
web.nvd.nist.gov
27
ibm
omnifind
enterprise edition
local users
privileges
arbitrary command

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

AI Score

6.5

Confidence

Low

EPSS

0

Percentile

5.1%

esRunCommand in IBM OmniFind Enterprise Edition before 9.1 allows local users to gain privileges by specifying an arbitrary command name as the first argument.

Affected configurations

Nvd
Node
ibmomnifindRange9.0-enterprise
OR
ibmomnifindMatch8.0-enterprise
OR
ibmomnifindMatch8.4-enterprise
OR
ibmomnifindMatch8.5-enterprise
VendorProductVersionCPE
ibmomnifind*cpe:2.3:a:ibm:omnifind:*:-:enterprise:*:*:*:*:*
ibmomnifind8.0cpe:2.3:a:ibm:omnifind:8.0:-:enterprise:*:*:*:*:*
ibmomnifind8.4cpe:2.3:a:ibm:omnifind:8.4:-:enterprise:*:*:*:*:*
ibmomnifind8.5cpe:2.3:a:ibm:omnifind:8.5:-:enterprise:*:*:*:*:*

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

AI Score

6.5

Confidence

Low

EPSS

0

Percentile

5.1%