CVE-2014-0868: Input Validation
RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics relies on client-side input validation, which allows remote authenticated users to bypass intended dual-control restrictions and modify data via a crafted XML document, as demonstrated by manipulation of read-only limit data.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0868?
CVE-2014-0868 is classified with a medium severity due to the possibility of remote authenticated users bypassing security restrictions.
How do I fix CVE-2014-0868?
To fix CVE-2014-0868, users should update to IBM Algo Credit Limits version 4.7.0.03 FP5 or later.
What types of systems are affected by CVE-2014-0868?
CVE-2014-0868 affects IBM Algo Credit Limits versions 4.5.0 to 4.7.0 before 4.7.0.03 FP5 and IBM Algorithmics software.
What are the risks associated with CVE-2014-0868?
The risks associated with CVE-2014-0868 include unauthorized data modification by authenticated users due to insufficient input validation.
Is user authentication required to exploit CVE-2014-0868?
Yes, exploiting CVE-2014-0868 requires remote authenticated user access to the system.