CVE-2014-0866: Medium severity ibm algo credit limits vulnerability
RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics sends cleartext credentials over HTTP, which allows remote attackers to obtain sensitive information by sniffing the network.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0866?
CVE-2014-0866 is classified as a moderate severity vulnerability due to the potential exposure of sensitive information.
How do I fix CVE-2014-0866?
To address CVE-2014-0866, upgrade to IBM Algo Credit Limits version 4.7.0.03 FP5 or later, which encrypts credentials during transmission.
What types of software are affected by CVE-2014-0866?
CVE-2014-0866 affects IBM Algo Credit Limits versions 4.5.0 through 4.7.0.03 FP5 and may impact users of IBM Algo One.
What kind of information is exposed by CVE-2014-0866?
CVE-2014-0866 exposes cleartext credentials which can be intercepted by remote attackers, compromising sensitive user data.
Is CVE-2014-0866 a local or remote vulnerability?
CVE-2014-0866 is a remote vulnerability that can be exploited from a distance by sniffing network traffic.