Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2014-0866

CWE-3104 documents4 sources
Severity
4.3MEDIUM
EPSS
18.5%
top 4.75%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedJul 7
Latest updateMay 14

Description

RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics sends cleartext credentials over HTTP, which allows remote attackers to obtain sensitive information by sniffing the network.

CVSS vector

AV:N/AC:M/C:P/I:N/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages1 packages

NVDibm/algo_credit_limits4.5.0, 4.7.0+1

🔴Vulnerability Details

2
GHSA
GHSA-2wh9-8pg9-7cgx: RICOS in IBM Algo Credit Limits (aka ACLM) 42022-05-14
CVEList
CVE-2014-0866: RICOS in IBM Algo Credit Limits (aka ACLM) 42014-07-07

💥Exploits & PoCs

1
Exploit-DB
IBM Algorithmics RICOS 4.5.0 < 4.7.0 - Multiple Vulnerabilities2014-07-01
CVE-2014-0866 (MEDIUM CVSS 4.3) | RICOS in IBM Algo Credit Limits (ak | cvebase.io