CVE-2010-3899 describes a denial-of-service vulnerability in IBM OmniFind Enterprise Edition versions 8.x and 9.x. The flaw allows remote web servers to trigger an infinite loop in the OmniFind web crawler by providing a specially crafted series of documents, due to the crawler's unlimited recursion depth. With a CVSS score of 5.0 (AV:N/AC:L/Au:N/C:N/I:N/A:P), this vulnerability is remotely exploitable with low attack complexity, leading to a partial denial of service. While not listed in CISA's KEV catalog, there is a public exploit available on ExploitDB, though there is no evidence of active exploitation, Metasploit modules, or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
8.0CPE matchmatch criteria | cpe:2.3:a:ibm:omnifind:8.0:-:enterprise:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:a:ibm:omnifind:9.0:-:enterprise:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:N/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.