5.5
CVSSv2

CVE-2020-4772

Published: 12/10/2020 Updated: 19/10/2020
CVSS v2 Base Score: 5.5 | Impact Score: 4.9 | Exploitability Score: 8
CVSS v3 Base Score: 8.1 | Impact Score: 5.2 | Exploitability Score: 2.8
VMScore: 490
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:P

Vulnerability Summary

An XML External Entity Injection (XXE) vulnerability may impact IBM Curam Social Program Management 7.0.9 and 7.0.10. A remote attacker could exploit this vulnerability to expose sensitive information, denial of service, server side request forgery or consume memory resources. IBM X-Force ID: 189150.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

ibm curam social program management 7.0.9.0

ibm curam social program management 7.0.10.0