CVE-2017-1106
Severity
5.4MEDIUM
EPSS
0.3%
top 51.38%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 28
Latest updateMay 17
Description
IBM Curam Social Program Management 5.2, 6.0, and 7.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 120744.
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:NExploitability: 2.3 | Impact: 2.7
Affected Packages2 packages
🔴Vulnerability Details
2💬Community
27Bugzilla▶
CVE-2017-5446 Mozilla: Out-of-bounds read when HTTP/2 DATA frames are sent with incorrect data (MFSA 2017-11, MFSA 2017-12)↗2017-04-19
Bugzilla
▶
Bugzilla▶
CVE-2017-5445 Mozilla: Uninitialized values used while parsing application/http-index-format content (MFSA 2017-11, MFSA 2017-12)↗2017-04-19
Bugzilla▶
CVE-2017-5443 Mozilla: Out-of-bounds write during BinHex decoding (MFSA 2017-11, MFSA 2017-12)↗2017-04-19
Bugzilla▶
CVE-2017-5456 Mozilla: Sandbox escape allowing local file system read access (MFSA 2017-12)↗2017-04-19