CVE-2014-4843
5.3
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Exploitability: 3.9 / Impact: 1.4
Source: NVD
Description
Curam Universal Access in IBM Curam Social Program Management (SPM) 6.0 SP2 before EP26, 6.0.4 before 6.0.4.6, and 6.0.5 before 6.0.5.5 iFix5 allows remote attackers to obtain sensitive information about internal caseworker usernames via vectors related to a URL.
Affected (12)
Products: Ibm: Curam Social Program Management
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 6.0 sp2 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 6.0.4.0 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 6.0.5.0 |
References (4)
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Timeline
No history available yet.