IBM.OmniFind.Security.Do.CSRF

2021-01-11 This signature was removed in version 16.995.

description-logoDescription

This indicates an attempt to exploit a Cross Site Request Forgery (CSRF) vulnerability in the administrator interface of IBM OmniFind Enterprise Edition.
The vulnerability is due to input validation errors in the "security.do" script. It can be exploited by attackers to cause malicious script code to be executed by a user's browser.

affected-products-logoAffected Products

IBM OmniFind Enterprise Edition before 9.1

Impact logoImpact

System Compromise: Remote script execution.

recomended-action-logoRecommended Actions

Contact your vendor for upgrade or patch information.

Coverage

IPS (Regular DB)
IPS (Extended DB)

Version Updates

Date Version Status Detail
2021-01-11 16.995
Removed