
CVE-2016-8923
https://notcve.org/view.php?id=CVE-2016-8923
20 Apr 2017 — IBM Curam Social Program Management 5.2, 6.0, and 7.0 contains a vulnerability that would allow an authorized user to obtain sensitive information from the profile of a higher privileged user that they should not have access to. IBM X-Force ID: 118536. IBM Curam Social Program Management 5.2, 6.0 y 7.0 contienen una vulnerabilidad que podría permitir a usuarios autorizados obtener información sensible del perfil de un usuario más privilegiado al que no debería tener acceso. IBM X-Force ID: 118536. • http://www.ibm.com/support/docview.wss?uid=swg22001774 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2016-9980
https://notcve.org/view.php?id=CVE-2016-9980
20 Apr 2017 — IBM Curam Social Program Management 5.2, 6.0, and 7.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 120256. IBM Curam Social Program Management 5.2, 6.0 y 7.0 es vulnerable a XSS. Esta vulnerabilidad permite a los usuarios integrar código JavaScript arbitrario en la interfaz de usuario Web, alterando así la ... • http://www.ibm.com/support/docview.wss?uid=swg22001779 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2016-6111
https://notcve.org/view.php?id=CVE-2016-6111
31 Mar 2017 — IBM Curam Social Program Management 6.0 and 7.0 are vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume all available memory resources. IBM Reference #: 2000833. IBM Curam Social Program Management 6.0 y 7.0 son vulnerables a una denegación de servicio, causada por un error de XML Entity Injection XXE al procesar datos XML. Un atacante remoto po... • http://www.ibm.com/support/docview.wss?uid=swg22000833 • CWE-611: Improper Restriction of XML External Entity Reference •

CVE-2015-5023
https://notcve.org/view.php?id=CVE-2015-5023
03 Jan 2016 — SQL injection vulnerability in IBM Curam Social Program Management 6.1 before 6.1.1 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors. Vulnerabilidad de inyección SQL en IBM Curam Social Program Management 6.1 en versiones anteriores a 6.1.1 permite a usuarios remotos autenticados ejecutar comandos SQL arbitrarios a través de vectores no especificados. • http://www-01.ibm.com/support/docview.wss?uid=swg21967851 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2014-6192
https://notcve.org/view.php?id=CVE-2014-6192
25 May 2015 — Cross-site scripting (XSS) vulnerability in IBM Curam Social Program Management 6.0 SP2 before EP26, 6.0.4 before 6.0.4.5 iFix10, 6.0.5 before 6.0.5.6, and 6.0.5.5a before 6.0.5.8 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL. Vulnerabilidad de XSS en IBM Curam Social Program Management 6.0 SP2 anterior a EP26, 6.0.4 anterior a 6.0.4.5 iFix10, 6.0.5 anterior a 6.0.5.6, y 6.0.5.5a anterior a 6.0.5.8 permite a usuarios remotos autenticados inyectar secuencias de co... • http://www-01.ibm.com/support/docview.wss?uid=swg21700252 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2014-6090
https://notcve.org/view.php?id=CVE-2014-6090
27 Apr 2015 — Multiple cross-site request forgery (CSRF) vulnerabilities in the (1) DataMappingEditorCommands, (2) DatastoreEditorCommands, and (3) IEGEditorCommands servlets in IBM Curam Social Program Management (SPM) 5.2 SP6 before EP6, 6.0 SP2 before EP26, 6.0.3 before 6.0.3.0 iFix8, 6.0.4 before 6.0.4.5 iFix10, and 6.0.5 before 6.0.5.6 allow remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences. Múltiples vulnerabilidades de CSRF en los servlets (1) DataMappingEditor... • http://www-01.ibm.com/support/docview.wss?uid=swg21697726 • CWE-352: Cross-Site Request Forgery (CSRF) •

CVE-2014-6092
https://notcve.org/view.php?id=CVE-2014-6092
27 Apr 2015 — IBM Curam Social Program Management (SPM) 5.2 before SP6 EP6, 6.0 SP2 before EP26, 6.0.4 before 6.0.4.6, and 6.0.5 before 6.0.5.6 requires failed-login handling for web-service accounts to have the same lockout policy as for standard user accounts, which makes it easier for remote attackers to cause a denial of service (web-service outage) by making many login attempts with a valid caseworker account name. IBM Curam Social Program Management (SPM) 5.2 anterior a SP6 EP6, 6.0 SP2 anterior a EP26, 6.0.4 anter... • http://www-01.ibm.com/support/docview.wss?uid=swg21697742 • CWE-17: DEPRECATED: Code •

CVE-2014-4804
https://notcve.org/view.php?id=CVE-2014-4804
14 Feb 2015 — Curam Universal Access in IBM Curam Social Program Management 5.2 before SP6 EP6, 6.0 SP2 before EP26, 6.0.4.5 before iFix007, 6.0.5.4 before iFix005, and 6.0.5.5 before iFix003, when SPI inclusion is enabled, allows remote attackers to obtain sensitive user data by visiting an unspecified page. Curam Universal Access en IBM Curam Social Program Management 5.2 anterior a SP6 EP6, 6.0 SP2 anterior a EP26, 6.0.4.5 anterior a iFix007, 6.0.5.4 anterior a iFix005, y 6.0.5.5 anterior a iFix003, cuando la inclusió... • http://www-01.ibm.com/support/docview.wss?uid=swg21695931 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2014-4803
https://notcve.org/view.php?id=CVE-2014-4803
13 Feb 2015 — CRLF injection vulnerability in the Universal Access implementation in IBM Curam Social Program Management 6.0 SP2 before EP26, 6.0.4 before 6.0.4.5 iFix007, and 6.0.5 before 6.0.5.5 iFix003, when WebSphere Application Server is not used, allows remote authenticated users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via an unspecified parameter. Vulnerabilidad de inyección CRLF en la implementación Universal Access en IBM Curam Social Program Management 6.0 SP2 anterior a EP2... • http://www-01.ibm.com/support/docview.wss?uid=swg21695925 •

CVE-2014-3096
https://notcve.org/view.php?id=CVE-2014-3096
10 Jan 2015 — Cross-site scripting (XSS) vulnerability in IBM Curam Social Program Management before 6.0.5.5a allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL. Vulnerabilidad de XSS en IBM Curam Social Program Management anterior a 6.0.5.5a permite a usuarios remotos autenticados inyectar secuencias de comandos web o HTML arbitrarios a través de una URL manipulada. • http://www-01.ibm.com/support/docview.wss?uid=swg21692994 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •