| |
Vulnerability CVE-2014-4804
Published: 2015-02-13 Modified: 2015-02-14
Description: |
Curam Universal Access in IBM Curam Social Program Management 5.2 before SP6 EP6, 6.0 SP2 before EP26, 6.0.4.5 before iFix007, 6.0.5.4 before iFix005, and 6.0.5.5 before iFix003, when SPI inclusion is enabled, allows remote attackers to obtain sensitive user data by visiting an unspecified page. |
Type:
CWE-200 (Information Exposure)
CVSS2 => (AV:N/AC:M/Au:N/C:P/I:N/A:N)
CVSS Base Score |
Impact Subscore |
Exploitability Subscore |
4.3/10 |
2.9/10 |
8.6/10 |
Exploit range |
Attack complexity |
Authentication |
Remote |
Medium |
No required |
Confidentiality impact |
Integrity impact |
Availability impact |
Partial |
None |
None |
References: |
http://www-01.ibm.com/support/docview.wss?uid=swg21695931
http://xforce.iss.net/xforce/xfdb/95306
|
|
|
Copyright 2024, cxsecurity.com
|
|
|