CVE-2014-0894: Infoleak
RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics allows context-dependent attackers to discover database credentials by reading the DbUser and DbPass fields in an XML document.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0894?
CVE-2014-0894 has been classified with a medium severity level due to the potential exposure of sensitive database credentials.
How do I fix CVE-2014-0894?
To fix CVE-2014-0894, upgrade IBM Algo Credit Limits to version 4.7.0.03 FP5 or later.
Which versions of IBM Algo Credit Limits are affected by CVE-2014-0894?
CVE-2014-0894 affects IBM Algo Credit Limits versions 4.5.0 through 4.7.0 before 4.7.0.03 FP5.
What type of vulnerability is CVE-2014-0894?
CVE-2014-0894 is a context-dependent vulnerability that allows attackers to access database credentials.
Can CVE-2014-0894 lead to data breaches?
Yes, CVE-2014-0894 can potentially result in data breaches if attackers exploit the vulnerability to access database credentials.