CVE-2020-4781Improper Input Validation in IBM Curam SPM

Severity
6.5MEDIUMNVD
EPSS
0.2%
top 58.10%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 12
Latest updateMay 24

Description

An improper input validation before calling java readLine() method may impact IBM Curam Social Program Management 7.0.9 and 7.0.10, which could result in a denial of service. IBM X-Force ID: 189159.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages2 packages

NVDibm/curam_social_program_management7.0.10.0, 7.0.9.0+1
CVEListV5ibm/curam_spm7.0.10, 7.0.9+1

🔴Vulnerability Details

2
GHSA
GHSA-wfr7-6ghr-5g47: An improper input validation before calling java readLine() method may impact IBM Curam Social Program Management 72022-05-24
CVEList
CVE-2020-4781: An improper input validation before calling java readLine() method may impact IBM Curam Social Program Management 72020-10-12

📋Vendor Advisories

1
Microsoft
Microsoft Exchange Remote Code Execution Vulnerability2020-12-08
CVE-2020-4781 — Improper Input Validation in IBM | cvebase