CVE-2014-0864

IBM Algo Credit Limits - CSRF

Title source: rule

Description

Multiple cross-site request forgery (CSRF) vulnerabilities in Executer in RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics allow remote attackers to hijack the authentication of arbitrary users for requests that change (1) a deal's currency or (2) a limit via a crafted XML document.

Exploits (1)

exploitdb WRITEUP
webappsjsp
https://www.exploit-db.com/exploits/33942

Scores

EPSS 0.0368
EPSS Percentile 88.0%

Details

CWE
CWE-352
Status published
Products (2)
ibm/algo_credit_limits 4.5.0
ibm/algo_credit_limits 4.7.0
Published Jul 07, 2014
Tracked Since Feb 18, 2026