Information Disclosure Vulnerability in IBM Curam Social Program Management
CVE-2014-4843
5.3MEDIUM
Summary
In particular versions of IBM Curam Social Program Management, a vulnerability exists that allows remote attackers to gain unauthorized access to sensitive internal information. By exploiting specific URL vectors, attackers may retrieve internal caseworker usernames, thereby posing significant risks to user privacy and security. Organizations using vulnerable versions must apply patches or mitigations to safeguard against potential attacks.
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved