CVE-2016-0261
https://notcve.org/view.php?id=CVE-2016-0261
Cross-site scripting (XSS) vulnerability in IBM Curam Social Program Management 6.0.0 before SP2 EP29, 6.0.4 before 6.0.4.6 iFix3, 6.0.5 before 6.0.5.9 iFix2, 6.1.0 before 6.1.0.1 iFix1, and 6.1.1 before 6.1.1.1 iFix1; and IBM Care Management 6.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 110604. Vulnerabilidad de Cross-Site Scripting (XSS) en IBM Curam Social Program Management, en versiones 6.0.0 anteriores a SP2 EP29; versiones 6.0.4 anteriores a la 6.0.4.6 iFix3; versiones 6.0.5 anteriores a la 6.0.5.9 iFix2; versiones 6.1.0 anteriores a la la 6.1.01 iFix1 y IBM Care Management 6.0 permite que atacantes remotos inyecten scripts web o HTML arbitrarios mediante vectores sin especificar. IBM X-Force ID: 110604. • http://www-01.ibm.com/support/docview.wss?uid=swg21981103 https://exchange.xforce.ibmcloud.com/vulnerabilities/110604 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2014-6191
https://notcve.org/view.php?id=CVE-2014-6191
Cross-site scripting (XSS) vulnerability in IBM Curam Social Program Management 6.0 SP2, 6.0.4, and 6.0.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 98568. Una vulnerabilidad de tipo Cross-Site Scripting (XSS) en las versiones 6.0 SP2, 6.0.4 y 6.0.5 de IBM Curam Social Program Management permite a atacantes remotos inyectar scripts web o HTML arbitrarios utilizando vectores no especificados. IBM X-Force ID: 98568. • http://www-01.ibm.com/support/docview.wss?uid=swg21698430 http://www.securityfocus.com/bid/73946 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2014-8903
https://notcve.org/view.php?id=CVE-2014-8903
IBM Curam Social Program Management 6.0 SP2 before EP26, 6.0.4 before 6.0.4.5iFix10 and 6.0.5 before 6.0.5.6 allows remote authenticated users to load arbitrary Java classes via unspecified vectors. IBM Curam Social Program Management 6.0 SP2 anterior a EP26, 6.0.4 anterior a 6.0.4.5iFix10 y 6.0.5 anterior a 6.0.5.6 permite que atacantes remotos carguen clases Java arbitrarias utilizando vectores no especificados. • http://www-01.ibm.com/support/docview.wss?uid=swg21700098 http://www.securityfocus.com/bid/73947 • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') •
CVE-2017-1106
https://notcve.org/view.php?id=CVE-2017-1106
IBM Curam Social Program Management 5.2, 6.0, and 7.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 120744. IBM Curam Social Program Management 5.2, 6.0 y 7.0 es vulnerable a ataques de tipo Cross-Site Scripting (XSS). Esta vulnerabilidad permite que los usuarios embeban código JavaScript arbitrario en la interfaz de usuario web, lo que altera las funcionalidades previstas. • http://www.ibm.com/support/docview.wss?uid=swg22004580 http://www.securityfocus.com/bid/99306 https://exchange.xforce.ibmcloud.com/vulnerabilities/120744 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2014-4843
https://notcve.org/view.php?id=CVE-2014-4843
Curam Universal Access in IBM Curam Social Program Management (SPM) 6.0 SP2 before EP26, 6.0.4 before 6.0.4.6, and 6.0.5 before 6.0.5.5 iFix5 allows remote attackers to obtain sensitive information about internal caseworker usernames via vectors related to a URL. Curam Universal Access en IBM Curam Social Program Management (SPM), versiones 6.0 SP2 anteriores a la EP26, 6.0.4 anteriores a la 6.0.4.6 y 6.0.5 anteriores a la 6.0.5.5 iFix5 permite a atacantes remotos obtener información sensible acerca de los nombres de los usuarios internos a través de vectores relacionados con la URL. • http://www-01.ibm.com/support/docview.wss?uid=swg21698548 http://www.securityfocus.com/bid/73943 • CWE-358: Improperly Implemented Security Check for Standard •