CVE-2010-3894 | ibm OmniFind 6.1/8.0/8.4/8.5 Administration Interface libffq.cryptionjni.so Java_com_ibm_es_oss_CryptionNative_ESEncrypt memory corruption (EDB-15474 / BID-44740)
A vulnerability, which was classified as very critical, was found in ibm OmniFind 6.1/8.0/8.4/8.5. Affected is the function Java_com_ibm_es_oss_CryptionNative_ESEncrypt in the library opt/IBM/es/lib/libffq.cryptionjni.so of the file /opt/IBM/es/lib/libffq.cryptionjni.so of the component Administration Interface. The manipulation leads to memory corruption.
This vulnerability is traded as CVE-2010-3894. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to add further authentication.