This page aggregates publicly disclosed CVE and security risk information related to omnis, with CVSS, EPSS, publication dates, and vulnerability intelligence data to help assess potential risk and remediation priority.
| CVE | 概要 | ソース | CVSS 最大値 | EPSS(%) | 公開 | 更新 |
|---|---|---|---|---|---|---|
| CVE-2023-38335 | Omnis Studio 10.22.00 has incorrect access control. It advertises a feature for making Omnis libraries "always private" - this is supposed to be an irreversible operation. However, due to implementation issues, "always private" Omnis libraries can be opened by the Omnis Studio browser by bypassing specific checks. This violates the expected behavior of an "irreversible operation". | [email protected] | 5.3 | 0.07% | 2023-07-20 | 2024-11-21 |
| CVE-2023-38334 | Omnis Studio 10.22.00 has incorrect access control. It advertises an irreversible feature for locking classes within Omnis libraries: it should be no longer possible to delete, view, change, copy, rename, duplicate, or print a locked class. Due to implementation issues, locked classes in Omnis libraries can be unlocked, and thus further analyzed and modified by Omnis Studio. This allows for further analyzing and also deleting, viewing, changing, copying, renaming, duplicating, or printing previo | [email protected] | 6.5 | 0.19% | 2023-07-20 | 2024-11-21 |
| CVE-2000-0449 | Omnis Studio 2.4 uses weak encryption (trivial encoding) for encrypting database fields. | [email protected] | 10.0 | 2.79% | 2000-05-01 | 2026-04-16 |