Omnifind

Vendor:

First CVE: Nov 12, 2010 · Active for 15 years

11
Total CVEs
More Total CVEs than 90% of tracked products
11.0
Avg CVEs / Year
Higher CVE frequency than 97% of tracked products
6.5
Avg CVSS
Higher Avg CVSS than 33% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Omnifind over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 12, 2010
15 years ago
Most Recent CVE
Nov 12, 2010
5,737 days ago

CVE Severity & Scoring

Omnifind11 CVEs
All CVEs353,240 CVEs
MediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown11 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown11 (100.0%)
User Interaction
None0 (0.0%)
Unknown11 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown11 (100.0%)

Top CVEs

Signals from CVEs in this product scope (11 CVEs).

11 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Stack-based buffer overflow in the Java_com_ibm_es_oss_CryptionNative_ESEncrypt function in /opt/IBM/es/lib/libffq.cryptionjni.so in the login form in the administration interface
Nov 12, 20109.345NOYES
esRunCommand in IBM OmniFind Enterprise Edition before 9.1 allows local users to gain privileges by specifying an arbitrary command name as the first argument.
Nov 12, 20107.233NOYES
The administrator interface in IBM OmniFind Enterprise Edition 8.x and 9.x does not restrict use of a session ID (aka SID) value to a single IP address, which allows remote attacke
Nov 12, 20107.532NOYES
Cross-site request forgery (CSRF) vulnerability in ESAdmin/security.do in the administrator interface in IBM OmniFind Enterprise Edition before 9.1 allows remote attackers to hijac
Nov 12, 20106.832NOYES
Untrusted search path vulnerability in estaskwrapper in IBM OmniFind Enterprise Edition before 9.1 allows local users to gain privileges via an ES_LIBRARY_PATH environment variable
Nov 12, 20106.930NOYES
IBM OmniFind Enterprise Edition 8.x and 9.x performs web crawls with an unlimited recursion depth, which allows remote web servers to cause a denial of service (infinite loop) via
Nov 12, 20105.029NOYES
The ESSearchApplication directory tree in IBM OmniFind Enterprise Edition 8.x and 9.x does not require authentication, which allows remote attackers to modify the server configurat
Nov 12, 20107.522NONO
Session fixation vulnerability in the login form in the administrator interface in IBM OmniFind Enterprise Edition 8.x and 9.x allows remote attackers to hijack web sessions by rep
Nov 12, 20106.822NONO
IBM OmniFind Enterprise Edition 8.x and 9.x does not properly restrict the cookie path of administrator (aka ESAdmin) cookies, which might allow remote attackers to bypass authenti
Nov 12, 20105.018NONO
ESSearchApplication/palette.do in IBM OmniFind Enterprise Edition 8.x and 9.x includes the administrator password in the HTML source code, which might allow remote attackers to obt
Nov 12, 20105.018NONO

Exploit Exposure

Signals from CVEs in this product scope (11 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
6 CVEs
54.5% of CVEs· 91st percentile

Social Chatter

Signals from CVEs in this product scope (11 CVEs).

Media Mentions

Signals from CVEs in this product scope (11 CVEs).

Top CNAs Publishing CVEs For Omnifind

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
9.156.41.6%01
9.066.11.8%02
8.596.31.3%04
8.4106.62.4%05
8.0116.52.4%06
6.128.16.5%02