First published: Mon Jul 07 2014(Updated: )
rcore6/main/addcookie.jsp in RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics allows remote attackers to create or modify cookies via the query string.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Algo Credit Limits | =4.5.0 | |
IBM Algo Credit Limits | =4.7.0 | |
IBM Algo One |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-0867 is rated as a medium severity vulnerability due to its potential to allow unauthorized cookie manipulation.
To fix CVE-2014-0867, upgrade to IBM Algorithmics ACLM version 4.7.0.03 FP5 or later.
CVE-2014-0867 enables remote attackers to manipulate cookies via the query string.
CVE-2014-0867 affects IBM Algo Credit Limits versions 4.5.0 through 4.7.0 before 4.7.0.03 FP5.
Organizations using affected versions of IBM Algorithmics are at risk from CVE-2014-0867.