CVE-2014-8903: Command Injection
IBM Curam Social Program Management 6.0 SP2 before EP26, 6.0.4 before 6.0.4.5iFix10 and 6.0.5 before 6.0.5.6 allows remote authenticated users to load arbitrary Java classes via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-8903?
CVE-2014-8903 has a medium severity rating because it allows remote authenticated users to load arbitrary Java classes.
How do I fix CVE-2014-8903?
To fix CVE-2014-8903, upgrade to IBM Curam Social Program Management version 6.0 SP2 EP26 or later.
What versions of IBM Curam Social Program Management are affected by CVE-2014-8903?
CVE-2014-8903 affects IBM Curam Social Program Management versions 6.0 SP2 before EP26, 6.0.4 before 6.0.4.5iFix10, and 6.0.5 before 6.0.5.6.
What type of attack does CVE-2014-8903 enable?
CVE-2014-8903 enables remote authenticated users to potentially execute arbitrary code on the server.
Who is vulnerable to CVE-2014-8903?
Organizations using the specified versions of IBM Curam Social Program Management could be vulnerable to attacks leveraging CVE-2014-8903.