Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-72qp-74c2-m684

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The ESSearchApplication directory tree in IBM OmniFind Enterprise Edition 8.x and 9.x does not require authentication, which allows remote attackers to modify the server configuration via a request to palette.do.

The ESSearchApplication directory tree in IBM OmniFind Enterprise Edition 8.x and 9.x does not require authentication, which allows remote attackers to modify the server configuration via a request to palette.do.

EPSS

Процентиль: 73%
0.00769
Низкий

Дефекты

CWE-287

Связанные уязвимости

nvd
около 15 лет назад

The ESSearchApplication directory tree in IBM OmniFind Enterprise Edition 8.x and 9.x does not require authentication, which allows remote attackers to modify the server configuration via a request to palette.do.

EPSS

Процентиль: 73%
0.00769
Низкий

Дефекты

CWE-287