3.5
CVSSv2

CVE-2014-0894

Published: 07/07/2014 Updated: 09/10/2018
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
VMScore: 355
Vector: AV:N/AC:M/Au:S/C:P/I:N/A:N

Vulnerability Summary

RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 up to and including 4.7.0 prior to 4.7.0.03 FP5 in IBM Algorithmics allows context-dependent malicious users to discover database credentials by reading the DbUser and DbPass fields in an XML document.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

ibm algorithmics -

ibm algo credit limits 4.5.0

ibm algo credit limits 4.7.0

Exploits

-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 SEC Consult Vulnerability Lab Security Advisory < 20140630-0 > ======================================================================= title: Multiple severe vulnerabilities product: IBM Algorithmics RICOS vulnerable version: 450 - 470 fixed version: 47003 ...
IBM Algorithmics RICOS versions 450 through 470 suffer from cross site scripting, cross site request forgery, information disclosure, data manipulation, broken encryption, and various other vulnerabilities ...