Curam Universal Access in IBM Curam Social Program Management (SPM) 6.0 SP2 before EP26, 6.0.4 before 6.0.4.6, and 6.0.5 before 6.0.5.5 iFix5 allows remote attackers to obtain sensitive information about internal caseworker usernames via vectors related to a URL.
References
Link | Resource |
---|---|
http://www-01.ibm.com/support/docview.wss?uid=swg21698548 | Vendor Advisory |
http://www.securityfocus.com/bid/73943 | Third Party Advisory VDB Entry |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Information
Published : 2017-06-08 09:29
Updated : 2017-06-15 07:16
NVD link : CVE-2014-4843
Mitre link : CVE-2014-4843
JSON object : View
CWE
CWE-358
Improperly Implemented Security Check for Standard
Products Affected
ibm
- curam_social_program_management