Omnifind
Vendor:
First CVE: Nov 12, 2010 · Active for 15 years
11
Total CVEs
More Total CVEs than 90% of tracked products
11.0
Avg CVEs / Year
Higher CVE frequency than 97% of tracked products
6.5
Avg CVSS
Higher Avg CVSS than 33% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Omnifind over time
Volume of CVEsAvg CVSS Base Score
First CVE
Nov 12, 2010
15 years ago
Most Recent CVE
Nov 12, 2010
5,737 days ago
CVE Severity & Scoring
Omnifind11 CVEs
64%
36%
All CVEs353,240 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown11 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown11 (100.0%)
User Interaction
None0 (0.0%)
Unknown11 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown11 (100.0%)
Top CVEs
Signals from CVEs in this product scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2010-3894HIGH Stack-based buffer overflow in the Java_com_ibm_es_oss_CryptionNative_ESEncrypt function in /opt/IBM/es/lib/libffq.cryptionjni.so in the login form in the administration interface | Nov 12, 2010 | 9.3 | 45 | NO | YES |
CVE-2010-3895HIGH esRunCommand in IBM OmniFind Enterprise Edition before 9.1 allows local users to gain privileges by specifying an arbitrary command name as the first argument. | Nov 12, 2010 | 7.2 | 33 | NO | YES |
CVE-2010-3893HIGH The administrator interface in IBM OmniFind Enterprise Edition 8.x and 9.x does not restrict use of a session ID (aka SID) value to a single IP address, which allows remote attacke | Nov 12, 2010 | 7.5 | 32 | NO | YES |
CVE-2010-3891MEDIUM Cross-site request forgery (CSRF) vulnerability in ESAdmin/security.do in the administrator interface in IBM OmniFind Enterprise Edition before 9.1 allows remote attackers to hijac | Nov 12, 2010 | 6.8 | 32 | NO | YES |
CVE-2010-4236MEDIUM Untrusted search path vulnerability in estaskwrapper in IBM OmniFind Enterprise Edition before 9.1 allows local users to gain privileges via an ES_LIBRARY_PATH environment variable | Nov 12, 2010 | 6.9 | 30 | NO | YES |
CVE-2010-3899MEDIUM IBM OmniFind Enterprise Edition 8.x and 9.x performs web crawls with an unlimited recursion depth, which allows remote web servers to cause a denial of service (infinite loop) via | Nov 12, 2010 | 5.0 | 29 | NO | YES |
CVE-2010-3896HIGH The ESSearchApplication directory tree in IBM OmniFind Enterprise Edition 8.x and 9.x does not require authentication, which allows remote attackers to modify the server configurat | Nov 12, 2010 | 7.5 | 22 | NO | NO |
CVE-2010-3892MEDIUM Session fixation vulnerability in the login form in the administrator interface in IBM OmniFind Enterprise Edition 8.x and 9.x allows remote attackers to hijack web sessions by rep | Nov 12, 2010 | 6.8 | 22 | NO | NO |
CVE-2010-3898MEDIUM IBM OmniFind Enterprise Edition 8.x and 9.x does not properly restrict the cookie path of administrator (aka ESAdmin) cookies, which might allow remote attackers to bypass authenti | Nov 12, 2010 | 5.0 | 18 | NO | NO |
CVE-2010-3897MEDIUM ESSearchApplication/palette.do in IBM OmniFind Enterprise Edition 8.x and 9.x includes the administrator password in the HTML source code, which might allow remote attackers to obt | Nov 12, 2010 | 5.0 | 18 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (11 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
6 CVEs
54.5% of CVEs· 91st percentile
Social Chatter
Signals from CVEs in this product scope (11 CVEs).
Media Mentions
Signals from CVEs in this product scope (11 CVEs).
Top CNAs Publishing CVEs For Omnifind
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 9.1 | 5 | 6.4 | 1.6% | 0 | 1 |
| 9.0 | 6 | 6.1 | 1.8% | 0 | 2 |
| 8.5 | 9 | 6.3 | 1.3% | 0 | 4 |
| 8.4 | 10 | 6.6 | 2.4% | 0 | 5 |
| 8.0 | 11 | 6.5 | 2.4% | 0 | 6 |
| 6.1 | 2 | 8.1 | 6.5% | 0 | 2 |