Cross-site scripting (XSS) vulnerability in IBM Curam Social Program Management (SPM) 6.0.4 before 6.0.4.5 iFix7 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
2014-09-23T21:55:04.990
2025-04-12T10:46:40.837
Deferred
CVSSv2: 3.5 (LOW)
AV:N/AC:M/Au:S/C:N/I:P/A:N
6.8
2.9
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | ibm | curam_social_program_management | 6.0.4.0 | Yes |
| Application | ibm | curam_social_program_management | 6.0.4.1 | Yes |
| Application | ibm | curam_social_program_management | 6.0.4.2 | Yes |
| Application | ibm | curam_social_program_management | 6.0.4.3 | Yes |
| Application | ibm | curam_social_program_management | 6.0.4.4 | Yes |
| Application | ibm | curam_social_program_management | 6.0.4.5 | Yes |