Lucene search

K
ibmIBM5611041158B7DE62BE51BD832AEA917D72A40F33A5FAD127DE7C957762E7A5DC
HistoryJun 17, 2018 - 1:06 p.m.

Security Bulletin: IBM Cúram Social Program Management is vulnerable to a SQL injection attack

2018-06-1713:06:09
www.ibm.com
6

EPSS

0.001

Percentile

28.0%

Summary

IBM Cúram Social Program Management is vulnerable to a SQL Injection attack. The attacker must already be authenticated and have access to the console.

Vulnerability Details

CVEID: CVE-2015-5023**
DESCRIPTION:** IBM Cúram Social Program Management is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements which could allow the attacker to view, add, modify or delete information in the back-end database.
CVSS Base Score: 5.4
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/106519 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N)

Affected Products and Versions

IBM Cúram Social Program Management 6.1


Remediation/Fixes

Product

| VRMF| Remiation/First Fix
—|—|—
Cúram SPM| 6.1| Visit IBM Fix Central and upgrade to 6.1.1

Workarounds and Mitigations

None


EPSS

0.001

Percentile

28.0%

Related for 5611041158B7DE62BE51BD832AEA917D72A40F33A5FAD127DE7C957762E7A5DC