{"api_version":"1","generated_at":"2026-07-23T05:01:31+00:00","cve":"CVE-2010-3897","urls":{"html":"https://cve.report/CVE-2010-3897","api":"https://cve.report/api/cve/CVE-2010-3897.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2010-3897","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2010-3897"},"summary":{"title":"CVE-2010-3897","description":"ESSearchApplication/palette.do in IBM OmniFind Enterprise Edition 8.x and 9.x includes the administrator password in the HTML source code, which might allow remote attackers to obtain sensitive information by leveraging read access to this file.","state":"PUBLISHED","assigner":"mitre","published_at":"2010-11-12 22:00:02","updated_at":"2026-04-29 01:13:23"},"problem_types":["CWE-255","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.vupen.com/english/advisories/2010/2933","name":"http://www.vupen.com/english/advisories/2010/2933","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/44740","name":"http://www.securityfocus.com/bid/44740","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"RETIRED: IBM OmniFind Multiple Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://security.fatihkilic.de/advisory/fkilic-sa-2010-ibm-omnifind.txt","name":"http://security.fatihkilic.de/advisory/fkilic-sa-2010-ibm-omnifind.txt","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Some seemingly benign web-site","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/514688/100/0/threaded","name":"http://www.securityfocus.com/archive/1/514688/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2010-3897","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2010-3897","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2010","cve_id":"3897","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"omnifind","cpe6":"8.0","cpe7":"-","cpe8":"enterprise","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"3897","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"omnifind","cpe6":"8.4","cpe7":"-","cpe8":"enterprise","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"3897","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"omnifind","cpe6":"8.5","cpe7":"-","cpe8":"enterprise","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"3897","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"omnifind","cpe6":"9.0","cpe7":"-","cpe8":"enterprise","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"3897","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"omnifind","cpe6":"9.1","cpe7":"-","cpe8":"enterprise","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T03:26:12.332Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"20101109 IBM OmniFind - several vulnerabilities","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/514688/100/0/threaded"},{"name":"44740","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/44740"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://security.fatihkilic.de/advisory/fkilic-sa-2010-ibm-omnifind.txt"},{"name":"ADV-2010-2933","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2010/2933"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2010-11-09T00:00:00.000Z","descriptions":[{"lang":"en","value":"ESSearchApplication/palette.do in IBM OmniFind Enterprise Edition 8.x and 9.x includes the administrator password in the HTML source code, which might allow remote attackers to obtain sensitive information by leveraging read access to this file."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-10T18:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"20101109 IBM OmniFind - several vulnerabilities","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/514688/100/0/threaded"},{"name":"44740","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/44740"},{"tags":["x_refsource_MISC"],"url":"http://security.fatihkilic.de/advisory/fkilic-sa-2010-ibm-omnifind.txt"},{"name":"ADV-2010-2933","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2010/2933"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2010-3897","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"ESSearchApplication/palette.do in IBM OmniFind Enterprise Edition 8.x and 9.x includes the administrator password in the HTML source code, which might allow remote attackers to obtain sensitive information by leveraging read access to this file."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"20101109 IBM OmniFind - several vulnerabilities","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/514688/100/0/threaded"},{"name":"44740","refsource":"BID","url":"http://www.securityfocus.com/bid/44740"},{"name":"http://security.fatihkilic.de/advisory/fkilic-sa-2010-ibm-omnifind.txt","refsource":"MISC","url":"http://security.fatihkilic.de/advisory/fkilic-sa-2010-ibm-omnifind.txt"},{"name":"ADV-2010-2933","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2010/2933"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2010-3897","datePublished":"2010-11-12T21:00:00.000Z","dateReserved":"2010-10-12T00:00:00.000Z","dateUpdated":"2024-08-07T03:26:12.332Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2010-11-12 22:00:02","lastModifiedDate":"2026-04-29 01:13:23","problem_types":["CWE-255","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:omnifind:8.0:-:enterprise:*:*:*:*:*","matchCriteriaId":"96D7BDA2-53EE-44A5-BA8E-DC1224B8B8E0"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:omnifind:8.4:-:enterprise:*:*:*:*:*","matchCriteriaId":"C73CA22A-FD69-43A1-AFC8-03A82D971AB2"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:omnifind:8.5:-:enterprise:*:*:*:*:*","matchCriteriaId":"6929217A-6689-460E-88AC-919B26A5C328"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:omnifind:9.0:-:enterprise:*:*:*:*:*","matchCriteriaId":"C955D88D-7E06-43EF-B7F8-5B059519E01B"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:omnifind:9.1:-:enterprise:*:*:*:*:*","matchCriteriaId":"8447721A-AE84-4AD5-A15A-51248887B65E"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2010","CveId":"3897","Ordinal":"1","Title":"CVE-2010-3897","CVE":"CVE-2010-3897","Year":"2010"},"notes":[{"CveYear":"2010","CveId":"3897","Ordinal":"1","NoteData":"ESSearchApplication/palette.do in IBM OmniFind Enterprise Edition 8.x and 9.x includes the administrator password in the HTML source code, which might allow remote attackers to obtain sensitive information by leveraging read access to this file.","Type":"Description","Title":"CVE-2010-3897"},{"CveYear":"2010","CveId":"3897","Ordinal":"2","NoteData":"2010-11-12","Type":"Other","Title":"Published"},{"CveYear":"2010","CveId":"3897","Ordinal":"3","NoteData":"2018-10-10","Type":"Other","Title":"Modified"}]}}}