First published: Fri Nov 12 2010(Updated: )
IBM OmniFind Enterprise Edition 8.x and 9.x does not properly restrict the cookie path of administrator (aka ESAdmin) cookies, which might allow remote attackers to bypass authentication by leveraging access to other pages on the web site.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM OmniFind | =9.0 | |
IBM OmniFind | =8.0 | |
IBM OmniFind | =8.5 | |
IBM OmniFind | =8.4 | |
IBM OmniFind | =9.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.