cve,link,title,description,vendor,products,score,severity,epss,cisa,cisa_published,article,ransomware,exploited,exploited_date,poc,trended,trended_no_1,trended_no_1_date,published,trended_score CVE-2022-22318,https://securityvulnerability.io/vulnerability/CVE-2022-22318,Session Management Vulnerability in IBM Curam Social Program Management,"IBM Curam Social Program Management versions 8.0.0 and 8.0.1 exhibit a session management flaw that fails to properly invalidate user sessions upon logout. This oversight allows an authenticated user the potential to impersonate another user within the system, posing a significant security risk. Proper session handling is essential for ensuring user integrity and confidentiality within applications. It is crucial for users of affected versions to be aware of this issue and to apply any patches or updates provided by IBM to mitigate the risks associated with this vulnerability.",IBM,Curam Social Program Management,5.9,MEDIUM,0.001449999981559813,false,,false,false,false,,,false,false,,2022-06-20T17:15:00.000Z,0 CVE-2022-22317,https://securityvulnerability.io/vulnerability/CVE-2022-22317,Session Management Flaw in IBM Curam Social Program Management,"The IBM Curam Social Program Management versions 8.0.0 and 8.0.1 are susceptible to a session management vulnerability. This issue arises due to the application failing to invalidate sessions post-logout, which may allow an authenticated user to impersonate another user. This vulnerability compromises user authentication and can lead to unauthorized access to sensitive information and functionalities within the system.",IBM,Curam Social Program Management,5.9,MEDIUM,0.001449999981559813,false,,false,false,false,,,false,false,,2022-06-20T17:15:00.000Z,0 CVE-2021-39068,https://securityvulnerability.io/vulnerability/CVE-2021-39068,Cross-Site Scripting Vulnerability in IBM Curam Social Program Management,"IBM Curam Social Program Management versions 8.0.1 and 7.0.11 contain a cross-site scripting vulnerability that permits attackers to inject arbitrary JavaScript code into the web interface. This may lead to the manipulation of user sessions, potentially exposing sensitive information such as credentials within trusted environments. Users and organizations relying on these versions should act promptly to mitigate this vulnerability to safeguard against potential exploitation.",IBM,Curam Social Program Management,5.4,MEDIUM,0.0005000000237487257,false,,false,false,false,,,false,false,,2022-04-11T19:15:00.000Z,0 CVE-2018-1654,https://securityvulnerability.io/vulnerability/CVE-2018-1654,,"IBM Curam Social Program Management 6.0.5, 6.1.1, 6.2.0, 7.0.1, and 7.0.3 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 144747.",IBM,Curam Social Program Management,6.8,MEDIUM,0.0012100000167265534,false,,false,false,false,,,false,false,,2018-12-11T16:29:00.000Z,0 CVE-2018-1900,https://securityvulnerability.io/vulnerability/CVE-2018-1900,,"IBM Curam Social Program Management 6.0.5, 6.1.1, 6.2.0, 7.0.1, and 7.0.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 152529.",IBM,Curam Social Program Management,5.4,MEDIUM,0.0006099999882280827,false,,false,false,false,,,false,false,,2018-12-11T16:29:00.000Z,0 CVE-2018-1671,https://securityvulnerability.io/vulnerability/CVE-2018-1671,,"IBM Curam Social Program Management 7.0.3 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-force ID: 144951.",IBM,Curam Social Program Management,6.1,MEDIUM,0.0008999999845400453,false,,false,false,false,,,false,false,,2018-12-10T14:00:00.000Z,0 CVE-2015-7401,https://securityvulnerability.io/vulnerability/CVE-2015-7401,,IBM Curam Social Program Management 6.1.x before 6.1.1.1 allows remote authenticated users to bypass intended access restrictions and obtain sensitive document information by guessing the document id. IBM X-Force ID: 107106.,IBM,Curam Social Program Management,4.3,MEDIUM,0.000750000006519258,false,,false,false,false,,,false,false,,2018-03-26T18:00:00.000Z,0 CVE-2016-0261,https://securityvulnerability.io/vulnerability/CVE-2016-0261,,"Cross-site scripting (XSS) vulnerability in IBM Curam Social Program Management 6.0.0 before SP2 EP29, 6.0.4 before 6.0.4.6 iFix3, 6.0.5 before 6.0.5.9 iFix2, 6.1.0 before 6.1.0.1 iFix1, and 6.1.1 before 6.1.1.1 iFix1; and IBM Care Management 6.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 110604.",IBM,Curam Social Program Management,5.4,MEDIUM,0.0006000000284984708,false,,false,false,false,,,false,false,,2018-03-12T21:00:00.000Z,0 CVE-2014-6191,https://securityvulnerability.io/vulnerability/CVE-2014-6191,,"Cross-site scripting (XSS) vulnerability in IBM Curam Social Program Management 6.0 SP2, 6.0.4, and 6.0.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 98568.",IBM,Curam Social Program Management,5.4,MEDIUM,0.0005099999834783375,false,,false,false,false,,,false,false,,2017-09-19T15:00:00.000Z,0 CVE-2014-8903,https://securityvulnerability.io/vulnerability/CVE-2014-8903,,"IBM Curam Social Program Management 6.0 SP2 before EP26, 6.0.4 before 6.0.4.5iFix10 and 6.0.5 before 6.0.5.6 allows remote authenticated users to load arbitrary Java classes via unspecified vectors.",IBM,Curam Social Program Management,8.8,HIGH,0.001290000043809414,false,,false,false,false,,,false,false,,2017-08-02T19:00:00.000Z,0 CVE-2014-4843,https://securityvulnerability.io/vulnerability/CVE-2014-4843,,"Curam Universal Access in IBM Curam Social Program Management (SPM) 6.0 SP2 before EP26, 6.0.4 before 6.0.4.6, and 6.0.5 before 6.0.5.5 iFix5 allows remote attackers to obtain sensitive information about internal caseworker usernames via vectors related to a URL.",IBM,Curam Social Program Management,5.3,MEDIUM,0.0008200000156648457,false,,false,false,false,,,false,false,,2017-06-08T16:00:00.000Z,0 CVE-2016-9978,https://securityvulnerability.io/vulnerability/CVE-2016-9978,,"IBM Curam Social Program Management 5.2, 6.0, and 7.0 could allow an authenticated attacker to disclose sensitive information. IBM X-Force ID: 120254.",IBM,Curam Social Program Management,4.3,MEDIUM,0.0005000000237487257,false,,false,false,false,,,false,false,,2017-04-20T21:00:00.000Z,0 CVE-2016-9980,https://securityvulnerability.io/vulnerability/CVE-2016-9980,,"IBM Curam Social Program Management 5.2, 6.0, and 7.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 120256.",IBM,Curam Social Program Management,5.4,MEDIUM,0.0005000000237487257,false,,false,false,false,,,false,false,,2017-04-20T21:00:00.000Z,0 CVE-2016-9979,https://securityvulnerability.io/vulnerability/CVE-2016-9979,,"IBM Curam Social Program Management 5.2, 6.0, and 7.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 120255.",IBM,Curam Social Program Management,5.4,MEDIUM,0.0005000000237487257,false,,false,false,false,,,false,false,,2017-04-20T21:00:00.000Z,0 CVE-2016-8923,https://securityvulnerability.io/vulnerability/CVE-2016-8923,,"IBM Curam Social Program Management 5.2, 6.0, and 7.0 contains a vulnerability that would allow an authorized user to obtain sensitive information from the profile of a higher privileged user that they should not have access to. IBM X-Force ID: 118536.",IBM,Curam Social Program Management,4.3,MEDIUM,0.0005000000237487257,false,,false,false,false,,,false,false,,2017-04-20T21:00:00.000Z,0 CVE-2015-5023,https://securityvulnerability.io/vulnerability/CVE-2015-5023,,SQL injection vulnerability in IBM Curam Social Program Management 6.1 before 6.1.1 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.,IBM,Curam Social Program Management,5.4,MEDIUM,0.0006399999838322401,false,,false,false,false,,,false,false,,2016-01-03T02:00:00.000Z,0 CVE-2015-7402,https://securityvulnerability.io/vulnerability/CVE-2015-7402,,Cross-site scripting (XSS) vulnerability in IBM Curam Social Program Management 6.1 before 6.1.1.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.,IBM,Curam Social Program Management,5.4,MEDIUM,0.0006000000284984708,false,,false,false,false,,,false,false,,2016-01-02T02:00:00.000Z,0 CVE-2014-6192,https://securityvulnerability.io/vulnerability/CVE-2014-6192,,"Cross-site scripting (XSS) vulnerability in IBM Curam Social Program Management 6.0 SP2 before EP26, 6.0.4 before 6.0.4.5 iFix10, 6.0.5 before 6.0.5.6, and 6.0.5.5a before 6.0.5.8 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.",IBM,Curam Social Program Management,,,0.0006300000241026282,false,,false,false,false,,,false,false,,2015-05-25T14:00:00.000Z,0 CVE-2014-6090,https://securityvulnerability.io/vulnerability/CVE-2014-6090,,"Multiple cross-site request forgery (CSRF) vulnerabilities in the (1) DataMappingEditorCommands, (2) DatastoreEditorCommands, and (3) IEGEditorCommands servlets in IBM Curam Social Program Management (SPM) 5.2 SP6 before EP6, 6.0 SP2 before EP26, 6.0.3 before 6.0.3.0 iFix8, 6.0.4 before 6.0.4.5 iFix10, and 6.0.5 before 6.0.5.6 allow remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.",IBM,Curam Social Program Management,,,0.002360000042244792,false,,false,false,false,,,false,false,,2015-04-27T01:00:00.000Z,0 CVE-2014-6092,https://securityvulnerability.io/vulnerability/CVE-2014-6092,,"IBM Curam Social Program Management (SPM) 5.2 before SP6 EP6, 6.0 SP2 before EP26, 6.0.4 before 6.0.4.6, and 6.0.5 before 6.0.5.6 requires failed-login handling for web-service accounts to have the same lockout policy as for standard user accounts, which makes it easier for remote attackers to cause a denial of service (web-service outage) by making many login attempts with a valid caseworker account name.",IBM,Curam Social Program Management,,,0.002460000105202198,false,,false,false,false,,,false,false,,2015-04-27T01:00:00.000Z,0 CVE-2014-4804,https://securityvulnerability.io/vulnerability/CVE-2014-4804,,"Curam Universal Access in IBM Curam Social Program Management 5.2 before SP6 EP6, 6.0 SP2 before EP26, 6.0.4.5 before iFix007, 6.0.5.4 before iFix005, and 6.0.5.5 before iFix003, when SPI inclusion is enabled, allows remote attackers to obtain sensitive user data by visiting an unspecified page.",IBM,Curam Social Program Management,,,0.001769999973475933,false,,false,false,false,,,false,false,,2015-02-14T02:00:00.000Z,0 CVE-2014-4803,https://securityvulnerability.io/vulnerability/CVE-2014-4803,,"CRLF injection vulnerability in the Universal Access implementation in IBM Curam Social Program Management 6.0 SP2 before EP26, 6.0.4 before 6.0.4.5 iFix007, and 6.0.5 before 6.0.5.5 iFix003, when WebSphere Application Server is not used, allows remote authenticated users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via an unspecified parameter.",IBM,Curam Social Program Management,,,0.0006799999973736703,false,,false,false,false,,,false,false,,2015-02-13T02:00:00.000Z,0 CVE-2014-3096,https://securityvulnerability.io/vulnerability/CVE-2014-3096,,Cross-site scripting (XSS) vulnerability in IBM Curam Social Program Management before 6.0.5.5a allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.,IBM,Curam Social Program Management,,,0.0006300000241026282,false,,false,false,false,,,false,false,,2015-01-10T02:00:00.000Z,0 CVE-2014-6091,https://securityvulnerability.io/vulnerability/CVE-2014-6091,,Cross-site scripting (XSS) vulnerability in IBM Curam Social Program Management (SPM) 6.0.4 before 6.0.4.5 iFix7 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.,IBM,Curam Social Program Management,,,0.0006300000241026282,false,,false,false,false,,,false,false,,2014-09-23T21:00:00.000Z,0 CVE-2014-3069,https://securityvulnerability.io/vulnerability/CVE-2014-3069,,"Multiple CRLF injection vulnerabilities in the Universal Access component in IBM Curam Social Program Management (SPM) 6.0.5.5, when WebSphere Application Server is not used, allow remote authenticated users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified parameters.",IBM,Curam Social Program Management,,,0.0009500000160187483,false,,false,false,false,,,false,false,,2014-08-12T00:00:00.000Z,0