CVE-2014-3013: XSS
Multiple cross-site scripting (XSS) vulnerabilities in IBM Curam Social Program Management 4.5 SP10 through 6.0.5.4 allow remote authenticated users to inject arbitrary web script or HTML via crafted input to a (1) custom JSP or (2) custom renderer.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-3013?
CVE-2014-3013 is classified as a medium severity vulnerability due to its ability to allow cross-site scripting attacks.
How do I fix CVE-2014-3013?
To fix CVE-2014-3013, apply the latest security patches provided by IBM for affected versions of Curam Social Program Management.
What versions of IBM Curam Social Program Management are affected by CVE-2014-3013?
CVE-2014-3013 affects versions 4.5 SP10 through 6.0.5.4 of IBM Curam Social Program Management.
Can CVE-2014-3013 be exploited by unauthenticated users?
No, CVE-2014-3013 can only be exploited by remote authenticated users.
What types of attacks are possible due to CVE-2014-3013?
CVE-2014-3013 allows attackers to inject arbitrary web scripts or HTML, leading to potential information disclosure or user session hijacking.