Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jx4v-m6x5-3c22

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The administrator interface in IBM OmniFind Enterprise Edition 8.x and 9.x does not restrict use of a session ID (aka SID) value to a single IP address, which allows remote attackers to perform arbitrary administrative actions by leveraging cookie theft, related to a "session impersonation" issue.

The administrator interface in IBM OmniFind Enterprise Edition 8.x and 9.x does not restrict use of a session ID (aka SID) value to a single IP address, which allows remote attackers to perform arbitrary administrative actions by leveraging cookie theft, related to a "session impersonation" issue.

EPSS

Процентиль: 92%
0.08987
Низкий

Связанные уязвимости

nvd
около 15 лет назад

The administrator interface in IBM OmniFind Enterprise Edition 8.x and 9.x does not restrict use of a session ID (aka SID) value to a single IP address, which allows remote attackers to perform arbitrary administrative actions by leveraging cookie theft, related to a "session impersonation" issue.

EPSS

Процентиль: 92%
0.08987
Низкий