First published: Fri Nov 12 2010(Updated: )
IBM OmniFind Enterprise Edition 8.x and 9.x performs web crawls with an unlimited recursion depth, which allows remote web servers to cause a denial of service (infinite loop) via a crafted series of documents.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM OmniFind | =9.0 | |
IBM OmniFind | =8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-3899 is classified as a denial of service vulnerability due to the potential for an infinite loop during web crawling.
To fix CVE-2010-3899, update IBM OmniFind Enterprise Edition to a version where this vulnerability is addressed.
CVE-2010-3899 affects IBM OmniFind Enterprise Edition versions 8.x and 9.x.
CVE-2010-3899 allows remote servers to conduct denial of service attacks through crafted document series.
Yes, CVE-2010-3899 can be exploited remotely by sending a specially crafted series of documents.