CVE-2014-8903

IBM Curam Social Program Management 6.0 SP2 before EP26, 6.0.4 before 6.0.4.5iFix10 and 6.0.5 before 6.0.5.6 allows remote authenticated users to load arbitrary Java classes via unspecified vectors.
Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
ibmCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 73%
VendorProductVersion
ibmcuram_social_program_management
6.0:sp2
ibmcuram_social_program_management
6.0.4.0
ibmcuram_social_program_management
6.0.4.1
ibmcuram_social_program_management
6.0.4.2
ibmcuram_social_program_management
6.0.4.3
ibmcuram_social_program_management
6.0.4.4
ibmcuram_social_program_management
6.0.4.5
ibmcuram_social_program_management
6.0.4.6
ibmcuram_social_program_management
6.0.4.7
ibmcuram_social_program_management
6.0.4.8
ibmcuram_social_program_management
6.0.4.9
ibmcuram_social_program_management
6.0.5
ibmcuram_social_program_management
6.0.5.0
ibmcuram_social_program_management
6.0.5.1
ibmcuram_social_program_management
6.0.5.2
ibmcuram_social_program_management
6.0.5.3
ibmcuram_social_program_management
6.0.5.4
ibmcuram_social_program_management
6.0.5.5
ibmcuram_social_program_management
6.0.5.6
ibmcuram_social_program_management
6.0.5.7
ibmcuram_social_program_management
6.0.5.8
ibmcuram_social_program_management
6.0.5.9
ibmcuram_social_program_management
6.0.5.10
𝑥
= Vulnerable software versions