CVE-2014-4804
Severity CVSS v4.0:
Pending analysis
Type:
CWE-200
Information Leak / Disclosure
Publication date:
14/02/2015
Last modified:
12/04/2025
Description
Curam Universal Access in IBM Curam Social Program Management 5.2 before SP6 EP6, 6.0 SP2 before EP26, 6.0.4.5 before iFix007, 6.0.5.4 before iFix005, and 6.0.5.5 before iFix003, when SPI inclusion is enabled, allows remote attackers to obtain sensitive user data by visiting an unspecified page.
Impact
Base Score 2.0
4.30
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:ibm:curam_social_program_management:*:sp6:*:*:*:*:*:* | 5.2 (including) | |
| cpe:2.3:a:ibm:curam_social_program_management:6.0:sp2:*:*:*:*:*:* | ||
| cpe:2.3:a:ibm:curam_social_program_management:6.0.4.5:*:*:*:*:*:*:* | ||
| cpe:2.3:a:ibm:curam_social_program_management:6.0.5.4:*:*:*:*:*:*:* | ||
| cpe:2.3:a:ibm:curam_social_program_management:6.0.5.5:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



