← Vulnerability feed

Vulnerability record · CVE-2014-0869 · published 7 July 2014

CVE-2014-0869: Ibm algo credit limits vulnerability

Ibm · Algo Credit Limits

The decrypt function in RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics does not require a key, which makes it easier for remote attackers to obtain cleartext passwords by sniffing the network and then providing a string argument to this function.

4.3 CVSS 2.0 Medium EPSS 5.5% · top 7.5% CWE-310 · CWE-310
4.3CVSS 2.0 base score
5.5%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
12References
17 Jun 2026Last modified by NVD

Description

The decrypt function in RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics does not require a key, which makes it easier for remote attackers to obtain cleartext passwords by sniffing the network and then providing a string argument to this function.

AV:N/AC:M/Au:N/C:P/I:N/A:N

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2014-0869 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

6.8CVE-2014-0864Ibm algo credit limits cross-site request forgery vulnerabilityMultiple cross-site request forgery (CSRF) vulnerabilities in Executer in RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0…EPSS 2.5%5.8CVE-2014-0867Ibm algo credit limits vulnerabilityrcore6/main/addcookie.jsp in RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics allows remote att…EPSS 5.1%4.9CVE-2014-0865Ibm algo credit limits improper input validation vulnerabilityRICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics relies on client-side input validation, which …EPSS 5.0%4.9CVE-2014-0868Ibm algo credit limits improper input validation vulnerabilityRICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics relies on client-side input validation, which …EPSS 4.3%4.3CVE-2014-0871Ibm algo credit limits information exposure vulnerabilityRICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics allows remote attackers to obtain potentially …EPSS 5.7%4.3CVE-2014-0866Ibm algo credit limits vulnerabilityRICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics sends cleartext credentials over HTTP, which a…EPSS 5.5%4.3CVE-2014-0870Ibm algo credit limits cross-site scripting vulnerabilityMultiple cross-site scripting (XSS) vulnerabilities in RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algo…EPSS 3.7%3.5CVE-2014-0894Ibm algo credit limits information exposure vulnerabilityRICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics allows context-dependent attackers to discover…EPSS 4.0%

Source: NIST National Vulnerability Database (record CVE-2014-0869), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.