Vulnerability Bulletins |
IBM Security Bulletin: IBM Cúram Social Program Management is vulnerable to Java reflection attack(CVE-2014-8903). |
|
| Affected software | IBM |
|
IBM Cúram Social Program Management is vulnerable to Java reflection attack caused by external input that is used to specify a class. A remote attacker could exploit this vulnerability by injecting arbitrary class names which will be subsequently loaded. CVE(s): CVE-2014-8903 Affected product(s) and affected version(s): IBM Cúram Social Program Management: V6.0 SP2, 6.0.4 and 6.0.5. NOTE: 6.0.5.5a is not affected Refer to the following reference URLs for remediation More info: https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_ibm_c%25C3%25BAram_social_program_management_is_vulnerable_to_java_reflection_attack_cve_2014_8903?lang=en_us |
|






