CVE-2014-0869
IBM Algo Credit Limits - Cryptographic Issue
Title source: ruleDescription
The decrypt function in RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics does not require a key, which makes it easier for remote attackers to obtain cleartext passwords by sniffing the network and then providing a string argument to this function.
Exploits (1)
References (6)
Scores
EPSS
0.1852
EPSS Percentile
95.3%
Details
CWE
CWE-310
Status
published
Products (3)
ibm/algo_credit_limits
4.5.0
ibm/algo_credit_limits
4.7.0
ibm/algorithmics
Published
Jul 07, 2014
Tracked Since
Feb 18, 2026