4.9
CVSSv2

CVE-2014-0868

Published: 07/07/2014 Updated: 09/10/2018
CVSS v2 Base Score: 4.9 | Impact Score: 4.9 | Exploitability Score: 6.8
VMScore: 495
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:P

Vulnerability Summary

RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 up to and including 4.7.0 prior to 4.7.0.03 FP5 in IBM Algorithmics relies on client-side input validation, which allows remote authenticated users to bypass intended dual-control restrictions and modify data via a crafted XML document, as demonstrated by manipulation of read-only limit data.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

ibm algorithmics -

ibm algo credit limits 4.5.0

ibm algo credit limits 4.7.0

Exploits

-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 SEC Consult Vulnerability Lab Security Advisory < 20140630-0 > ======================================================================= title: Multiple severe vulnerabilities product: IBM Algorithmics RICOS vulnerable version: 450 - 470 fixed version: 47003 ...
IBM Algorithmics RICOS versions 450 through 470 suffer from cross site scripting, cross site request forgery, information disclosure, data manipulation, broken encryption, and various other vulnerabilities ...