Vulnerability Bulletins

IBM Security Bulletin: IBM Cúram Universal Access is vulnerable to CRLF Injection attack when not deployed on IBM WebSphere. (CVE-2014-4803)

   
Affected software IBM
 
The Universal Access component of IBM Cúram Social Program Management, when not deployed on IBM WebSphere Application Server, is vulnerable to CRLF Injection attack; this is caused by improper sanitization/escaping of a parameter on one page. CVE(s): CVE-2014-4803 Affected product(s) and affected version(s): The Curam product is affected in versions: 6.0 SP2 6.0.4 6.0.5 Refer to the following reference URLs for remediation and additional vulnerability details: Source Bulletin:

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_ibm_c%25C3%25BAram_universal_access_is_vulnerable_to_crlf_injection_attack_when_not_deployed_on_ibm_websphere_cve_2014_4803?lang=en_us