First published: Thu Jan 11 2018(Updated: )
IBM Curam Social Program Management 6.0.5, 6.1.1, 6.2.0, and 7.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 134921.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Curam Social Program Management | =6.0.5.0 | |
IBM Curam Social Program Management | =6.0.5.1 | |
IBM Curam Social Program Management | =6.0.5.2 | |
IBM Curam Social Program Management | =6.0.5.3 | |
IBM Curam Social Program Management | =6.0.5.4 | |
IBM Curam Social Program Management | =6.0.5.5 | |
IBM Curam Social Program Management | =6.0.5.6 | |
IBM Curam Social Program Management | =6.0.5.7 | |
IBM Curam Social Program Management | =6.0.5.8 | |
IBM Curam Social Program Management | =6.0.5.9 | |
IBM Curam Social Program Management | =6.0.5.10 | |
IBM Curam Social Program Management | =6.1.0.0 | |
IBM Curam Social Program Management | =6.1.0.1 | |
IBM Curam Social Program Management | =6.1.0.2 | |
IBM Curam Social Program Management | =6.1.0.3 | |
IBM Curam Social Program Management | =6.1.0.4 | |
IBM Curam Social Program Management | =6.1.0.5 | |
IBM Curam Social Program Management | =6.1.1.0 | |
IBM Curam Social Program Management | =6.1.1.1 | |
IBM Curam Social Program Management | =6.1.1.2 | |
IBM Curam Social Program Management | =6.1.1.3 | |
IBM Curam Social Program Management | =6.1.1.4 | |
IBM Curam Social Program Management | =6.1.1.5 | |
IBM Curam Social Program Management | =6.1.1.6 | |
IBM Curam Social Program Management | =6.2.0.0 | |
IBM Curam Social Program Management | =6.2.0.1 | |
IBM Curam Social Program Management | =6.2.0.2 | |
IBM Curam Social Program Management | =6.2.0.3 | |
IBM Curam Social Program Management | =6.2.0.4 | |
IBM Curam Social Program Management | =6.2.0.5 | |
IBM Curam Social Program Management | =6.2.0.6 | |
IBM Curam Social Program Management | =7.0.0.0 | |
IBM Curam Social Program Management | =7.0.0.1 | |
IBM Curam Social Program Management | =7.0.0.2 | |
IBM Curam Social Program Management | =7.0.1.0 | |
IBM Curam Social Program Management | =7.0.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-1739 is a vulnerability in IBM Curam Social Program Management that allows users to embed arbitrary JavaScript code in the Web UI, potentially leading to credentials disclosure.
The severity of CVE-2017-1739 is medium, with a CVSS score of 5.4.
CVE-2017-1739 allows attackers to carry out cross-site scripting attacks on IBM Curam Social Program Management, potentially leading to credentials disclosure within a trusted session.
Yes, IBM has released patches to address the vulnerability in different versions of IBM Curam Social Program Management. Please refer to the IBM Security Bulletin for more information.
You can find more information about CVE-2017-1739 in the IBM Security Bulletin, SecurityFocus, and IBM X-Force Exchange.