CVE-2014-0868
RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics relies on client-side input validation, which allows remote authenticated users to bypass intended dual-control restrictions and modify data via a crafted XML document, as demonstrated by manipulation of read-only limit data.
Ver en NVDSeveridad
N/A
EPSS
Probabilidad de explotación (próx. 30 días): 0.0960 (9.6%)
Percentil: 92.9%
EPSS: 2026-05-06
Afecta
ibm:algo_credit_limitsibm:algorithmicsDescripción técnica
RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics relies on client-side input validation, which allows remote authenticated users to bypass intended dual-control restrictions and modify data via a crafted XML document, as demonstrated by manipulation of read-only limit data.
Publicada: 7/7/2014, 11:01:28
Última modificación: 6/5/2026, 22:30:45
Referencias
- http://packetstormsecurity.com/files/127304/IBM-Algorithmics-RICOS-Disclosure-XSS-CSRF.html
- http://seclists.org/fulldisclosure/2014/Jun/173
- http://secunia.com/advisories/59296
- http://www-01.ibm.com/support/docview.wss?uid=swg21675881
- http://www.securityfocus.com/archive/1/532598/100/0/threaded
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90942
- https://www.sec-consult.com/fxdata/seccons/prod/temedia/advisories_txt/20140630-0_IBM_Algorithmics_RICOS_multiple_vulnerabilities_v10.txt
- http://packetstormsecurity.com/files/127304/IBM-Algorithmics-RICOS-Disclosure-XSS-CSRF.html