Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
IBM OmniFind Enterprise Edition 8.x and 9.x does not properly restrict the cookie path of administrator (aka ESAdmin) cookies, which might allow remote attackers to bypass authentication by leveraging access to other pages on the web site.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
IBM OmniFind权限许可和访问控制漏洞
Vulnerability Description
IBM OmniFind Enterprise Edition提供可靠的企业内部网,公共Web站点和信息提取应用。 IBM OmniFind Enterprise Edition 8.x和9.x版本不能正确限制管理员(又名ESAdmin)cookie的cookie路径。远程攻击者可以通过对web站点其他页面的访问绕过认证。
CVSS Information
N/A
Vulnerability Type
N/A