CVE-2014-4843: IBM Curam Social Program Management

Medium severity, CVSS 5.3. EPSS: 1.3% chance of exploitation in the next 30 days.

Curam Universal Access in IBM Curam Social Program Management (SPM) 6.0 SP2 before EP26, 6.0.4 before 6.0.4.6, and 6.0.5 before 6.0.5.5 iFix5 allows remote attackers to obtain sensitive information about internal caseworker usernames via vectors related to a URL.

Affected products

  • IBM Curam Social Program Management: version 6.0 only; version 6.0.4.0 only; version 6.0.4.1 only; version 6.0.4.2 only; version 6.0.4.3 only; version 6.0.4.4 only; …

Published 2017-06-08. Last modified 2026-06-17.