Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2014-4804


Curam Universal Access in IBM Curam Social Program Management 5.2 before SP6 EP6, 6.0 SP2 before EP26, 6.0.4.5 before iFix007, 6.0.5.4 before iFix005, and 6.0.5.5 before iFix003, when SPI inclusion is enabled, allows remote attackers to obtain sensitive user data by visiting an unspecified page.


Published

2015-02-14T02:59:00.067

Last Modified

2025-04-12T10:46:40.837

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 4.3 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:P/I:N/A:N

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

8.6

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-200

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application ibm curam_social_program_management ≤ 5.2 Yes
Application ibm curam_social_program_management 6.0 Yes
Application ibm curam_social_program_management 6.0.4.5 Yes
Application ibm curam_social_program_management 6.0.5.4 Yes
Application ibm curam_social_program_management 6.0.5.5 Yes

References