VYPR
Unrated severityNVD Advisory· Published Feb 14, 2015· Updated May 6, 2026

CVE-2014-4804

CVE-2014-4804

Description

Curam Universal Access in IBM Curam Social Program Management 5.2 before SP6 EP6, 6.0 SP2 before EP26, 6.0.4.5 before iFix007, 6.0.5.4 before iFix005, and 6.0.5.5 before iFix003, when SPI inclusion is enabled, allows remote attackers to obtain sensitive user data by visiting an unspecified page.

Affected products

5
  • cpe:2.3:a:ibm:curam_social_program_management:*:sp6:*:*:*:*:*:*+ 4 more
    • cpe:2.3:a:ibm:curam_social_program_management:*:sp6:*:*:*:*:*:*range: <=5.2
    • cpe:2.3:a:ibm:curam_social_program_management:6.0:sp2:*:*:*:*:*:*
    • cpe:2.3:a:ibm:curam_social_program_management:6.0.4.5:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:curam_social_program_management:6.0.5.4:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:curam_social_program_management:6.0.5.5:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.