CVE-2010-3895
published 2010-11-12CVE-2010-3895: esRunCommand in IBM OmniFind Enterprise Edition before 9.1 allows local users to gain privileges by specifying an arbitrary command name as the first argument.
PriorityP337high7.2CVSS 2.0
AVLACLAuNCCICAC
EXPLOIT
EPSS
0.78%
51.7th percentile
esRunCommand in IBM OmniFind Enterprise Edition before 9.1 allows local users to gain privileges by specifying an arbitrary command name as the first argument.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | omnifind | <= 9.0 | — |
| ibm | omnifind | — | — |
| ibm | omnifind | — | — |
| ibm | omnifind | — | — |
| ibm | omnifind | — | — |
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-p9qc-jx9p-h9xh: Untrusted search path vulnerability in estaskwrapper in IBM OmniFind Enterprise Edition before 9
ghsa_unreviewed·2022-05-14·CVSS 7.2
CVE-2010-4236 [HIGH] GHSA-p9qc-jx9p-h9xh: Untrusted search path vulnerability in estaskwrapper in IBM OmniFind Enterprise Edition before 9
Untrusted search path vulnerability in estaskwrapper in IBM OmniFind Enterprise Edition before 9.1 allows local users to gain privileges via an ES_LIBRARY_PATH environment variable and a modified PATH environment variable, which is used during execution of the estasklight program, a different vulnerability than CVE-2010-3895.
GHSA
GHSA-rhc9-w9j2-xc59: esRunCommand in IBM OmniFind Enterprise Edition before 9
ghsa_unreviewed·2022-05-14
CVE-2010-3895 [HIGH] GHSA-rhc9-w9j2-xc59: esRunCommand in IBM OmniFind Enterprise Edition before 9
esRunCommand in IBM OmniFind Enterprise Edition before 9.1 allows local users to gain privileges by specifying an arbitrary command name as the first argument.
No detection rules found.
No writeups or analysis indexed.
http://security.fatihkilic.de/advisory/fkilic-sa-2010-ibm-omnifind.txthttp://www.exploit-db.com/exploits/15475http://www.securityfocus.com/archive/1/514688/100/0/threadedhttp://www.securityfocus.com/bid/44740http://www.vupen.com/english/advisories/2010/2933http://security.fatihkilic.de/advisory/fkilic-sa-2010-ibm-omnifind.txthttp://www.exploit-db.com/exploits/15475http://www.securityfocus.com/archive/1/514688/100/0/threadedhttp://www.securityfocus.com/bid/44740http://www.vupen.com/english/advisories/2010/2933
2010-11-12
Published