cbcvebase.
CVE-2020-4772
published 2020-10-12

CVE-2020-4772: An XML External Entity Injection (XXE) vulnerability may impact IBM Curam Social Program Management 7.0.9 and 7.0.10. A remote attacker could exploit this…

high8.1CVSS 3.1
AVNACLPRLUINSUCHINAH
An XML External Entity Injection (XXE) vulnerability may impact IBM Curam Social Program Management 7.0.9 and 7.0.10. A remote attacker could exploit this vulnerability to expose sensitive information, denial of service, server side request forgery or consume memory resources. IBM X-Force ID: 189150.

Affected

4 ranges
VendorProductVersion rangeFixed in
ibmcuram_social_program_management
ibmcuram_social_program_management
ibmcuram_spm
ibmcuram_spm