IBM OmniFind "ESSearchApplication" Security Bypass Issue

  Bookmark
 and Share

IBM OmniFind is an application used for knowledge driven search. A security bypass issue affects the configuration panel of the application. Specifically, it fails to authenticate a user before allowing access to the pages in the "ESSearchApplication" directory. IBM OmniFind versions 8.5 and 9.0 are affected.

Ref: http://www.securityfocus.com/archive/1/514688

10.48.21 - CVE: CVE-2010-3896
Platform: Cross Platform