CVE-2016-6111: IBM Curam Social Program Management

Critical severity, CVSS 9.1. EPSS: 2.1% chance of exploitation in the next 30 days.

IBM Curam Social Program Management 6.0 and 7.0 are vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume all available memory resources. IBM Reference #: 2000833.

Affected products

  • IBM Curam Social Program Management: version 5.2 only; version 6.0 only; version 6.0.0 only; version 6.0.4.0 only; version 6.0.4.1 only; version 6.0.4.2 only; …

Published 2017-03-31. Last modified 2026-06-17.