CVE-2014-3013

Multiple cross-site scripting (XSS) vulnerabilities in IBM Curam Social Program Management 4.5 SP10 through 6.0.5.4 allow remote authenticated users to inject arbitrary web script or HTML via crafted input to a (1) custom JSP or (2) custom renderer.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
3.5 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:S/C:N/I:P/A:N
ibmCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 41%
VendorProductVersion
ibmcuram_social_program_management
4.5:sp10
ibmcuram_social_program_management
5.0
ibmcuram_social_program_management
5.2:sp1
ibmcuram_social_program_management
5.2:sp4
ibmcuram_social_program_management
6.0
ibmcuram_social_program_management
6.0.3.0
ibmcuram_social_program_management
6.0.4.0
ibmcuram_social_program_management
6.0.4.1
ibmcuram_social_program_management
6.0.4.2
ibmcuram_social_program_management
6.0.4.3
ibmcuram_social_program_management
6.0.4.4
ibmcuram_social_program_management
6.0.4.5
ibmcuram_social_program_management
6.0.5.0
ibmcuram_social_program_management
6.0.5.1
ibmcuram_social_program_management
6.0.5.2
ibmcuram_social_program_management
6.0.5.3
ibmcuram_social_program_management
6.0.5.4
𝑥
= Vulnerable software versions