Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2014-4804

Опубликовано: 14 фев. 2015
Источник: nvd
CVSS2: 4.3
EPSS Низкий

Описание

Curam Universal Access in IBM Curam Social Program Management 5.2 before SP6 EP6, 6.0 SP2 before EP26, 6.0.4.5 before iFix007, 6.0.5.4 before iFix005, and 6.0.5.5 before iFix003, when SPI inclusion is enabled, allows remote attackers to obtain sensitive user data by visiting an unspecified page.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:ibm:curam_social_program_management:*:sp6:*:*:*:*:*:*
Версия до 5.2 (включая)
cpe:2.3:a:ibm:curam_social_program_management:6.0:sp2:*:*:*:*:*:*
cpe:2.3:a:ibm:curam_social_program_management:6.0.4.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:curam_social_program_management:6.0.5.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:curam_social_program_management:6.0.5.5:*:*:*:*:*:*:*

EPSS

Процентиль: 45%
0.00225
Низкий

4.3 Medium

CVSS2

Дефекты

CWE-200

Связанные уязвимости

github
больше 3 лет назад

Curam Universal Access in IBM Curam Social Program Management 5.2 before SP6 EP6, 6.0 SP2 before EP26, 6.0.4.5 before iFix007, 6.0.5.4 before iFix005, and 6.0.5.5 before iFix003, when SPI inclusion is enabled, allows remote attackers to obtain sensitive user data by visiting an unspecified page.

EPSS

Процентиль: 45%
0.00225
Низкий

4.3 Medium

CVSS2

Дефекты

CWE-200