Ibm Algo Credit Limits vulnerabilities

9 known vulnerabilities affecting ibm/algo_credit_limits.

Total CVEs
9
CISA KEV
0
Public exploits
9
Exploited in wild
0
Severity breakdown
MEDIUM8LOW1

Vulnerabilities

Page 1 of 1
CVE-2014-0871MEDIUMCVSS 4.3PoCv4.5.0v4.7.02014-07-07
CVE-2014-0871 [MEDIUM] CWE-200 CVE-2014-0871: RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmi RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics allows remote attackers to obtain potentially sensitive Tomcat stack-trace information via non-printing characters in a cookie to the /classes/ URI, as demonstrated by the \x00 character.
nvd
CVE-2014-0866MEDIUMCVSS 4.3PoCv4.5.0v4.7.02014-07-07
CVE-2014-0866 [MEDIUM] CWE-310 CVE-2014-0866: RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmi RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics sends cleartext credentials over HTTP, which allows remote attackers to obtain sensitive information by sniffing the network.
nvd
CVE-2014-0868MEDIUMCVSS 4.9PoCv4.5.0v4.7.02014-07-07
CVE-2014-0868 [MEDIUM] CWE-20 CVE-2014-0868: RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmi RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics relies on client-side input validation, which allows remote authenticated users to bypass intended dual-control restrictions and modify data via a crafted XML document, as demonstrated by manipulation of read-only limit data.
nvd
CVE-2014-0864MEDIUMCVSS 6.8PoCv4.5.0v4.7.02014-07-07
CVE-2014-0864 [MEDIUM] CWE-352 CVE-2014-0864: Multiple cross-site request forgery (CSRF) vulnerabilities in Executer in RICOS in IBM Algo Credit L Multiple cross-site request forgery (CSRF) vulnerabilities in Executer in RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics allow remote attackers to hijack the authentication of arbitrary users for requests that change (1) a deal's currency or (2) a limit via a crafted XML document.
nvd
CVE-2014-0865MEDIUMCVSS 4.9PoCv4.5.0v4.7.02014-07-07
CVE-2014-0865 [MEDIUM] CWE-20 CVE-2014-0865: RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmi RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics relies on client-side input validation, which allows remote authenticated users to bypass intended dual-control restrictions and modify data via crafted serialized objects, as demonstrated by limit manipulations.
nvd
CVE-2014-0870MEDIUMCVSS 4.3PoCv4.5.0v4.7.02014-07-07
CVE-2014-0870 [MEDIUM] CWE-79 CVE-2014-0870: Multiple cross-site scripting (XSS) vulnerabilities in RICOS in IBM Algo Credit Limits (aka ACLM) 4. Multiple cross-site scripting (XSS) vulnerabilities in RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics allow remote attackers to inject arbitrary web script or HTML via (1) the Message parameter to rcore6/main/showerror.jsp, (2) the ButtonsetClass parameter to rcore6/main/buttonset.jsp, (3) the MBN
nvd
CVE-2014-0869MEDIUMCVSS 4.3PoCv4.5.0v4.7.02014-07-07
CVE-2014-0869 [MEDIUM] CWE-310 CVE-2014-0869: The decrypt function in RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0. The decrypt function in RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics does not require a key, which makes it easier for remote attackers to obtain cleartext passwords by sniffing the network and then providing a string argument to this function.
nvd
CVE-2014-0867MEDIUMCVSS 5.8PoCv4.5.0v4.7.02014-07-07
CVE-2014-0867 [MEDIUM] CVE-2014-0867: rcore6/main/addcookie.jsp in RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4 rcore6/main/addcookie.jsp in RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics allows remote attackers to create or modify cookies via the query string.
nvd
CVE-2014-0894LOWCVSS 3.5PoCv4.5.0v4.7.02014-07-07
CVE-2014-0894 [LOW] CWE-200 CVE-2014-0894: RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmi RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics allows context-dependent attackers to discover database credentials by reading the DbUser and DbPass fields in an XML document.
nvd