CVE-2014-0869: Medium severity ibm algo credit limits vulnerability
The decrypt function in RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics does not require a key, which makes it easier for remote attackers to obtain cleartext passwords by sniffing the network and then providing a string argument to this function.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0869?
CVE-2014-0869 is considered a high severity vulnerability due to its potential to expose cleartext passwords.
How do I fix CVE-2014-0869?
To fix CVE-2014-0869, upgrade to IBM Algo Credit Limits version 4.7.0.03 FP5 or later.
What are the affected versions related to CVE-2014-0869?
CVE-2014-0869 affects IBM Algo Credit Limits versions 4.5.0 through 4.7.0 before 4.7.0.03 FP5.
What types of attacks can exploit CVE-2014-0869?
CVE-2014-0869 can be exploited by remote attackers sniffing the network to obtain cleartext passwords.
Is there a workaround for CVE-2014-0869?
There are no documented workarounds for CVE-2014-0869; the recommended action is to upgrade the software.