Vulnerability Bulletins

IBM Security Bulletin: IBM Cúram is susceptible to a Open Source CKEditor vulnerability (CVE-2014-5191)

   
Affected software IBM
 
IBM Cúram Social Program Management is vulnerable to Reflected Cross-Site Scripting(XSS). This is caused by improper sanitization of user-supplied data in the Preview Plugin for CKEditor. CVE(s): CVE-2014-5191 Affected product(s) and affected version(s): The Cúram product is affected in versions: 6.0.4.4 6.0.4.5 6.0.5 The product version 6.0.5.5a is NOT affected. Refer to the following reference URLs for remediation and additional vulnerability details: Source

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_ibm_c%25C3%25BAram_is_susceptible_to_a_open_source_ckeditor_vulnerability_cve_2014_5191?lang=en_us