Lucene search

K
cveMitreCVE-2010-3897
HistoryNov 12, 2010 - 10:00 p.m.

CVE-2010-3897

2010-11-1222:00:02
CWE-255
mitre
web.nvd.nist.gov
22
ibm
omnifind
cve-2010-3897
password exposure
security vulnerability
nvd

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

5.9

Confidence

Low

EPSS

0.003

Percentile

70.2%

ESSearchApplication/palette.do in IBM OmniFind Enterprise Edition 8.x and 9.x includes the administrator password in the HTML source code, which might allow remote attackers to obtain sensitive information by leveraging read access to this file.

Affected configurations

Nvd
Node
ibmomnifindMatch8.0-enterprise
OR
ibmomnifindMatch8.4-enterprise
OR
ibmomnifindMatch8.5-enterprise
OR
ibmomnifindMatch9.0-enterprise
OR
ibmomnifindMatch9.1-enterprise
VendorProductVersionCPE
ibmomnifind8.0cpe:2.3:a:ibm:omnifind:8.0:-:enterprise:*:*:*:*:*
ibmomnifind8.4cpe:2.3:a:ibm:omnifind:8.4:-:enterprise:*:*:*:*:*
ibmomnifind8.5cpe:2.3:a:ibm:omnifind:8.5:-:enterprise:*:*:*:*:*
ibmomnifind9.0cpe:2.3:a:ibm:omnifind:9.0:-:enterprise:*:*:*:*:*
ibmomnifind9.1cpe:2.3:a:ibm:omnifind:9.1:-:enterprise:*:*:*:*:*

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

5.9

Confidence

Low

EPSS

0.003

Percentile

70.2%