{"api_version":"1","generated_at":"2026-06-23T08:36:06+00:00","cve":"CVE-2026-8636","urls":{"html":"https://cve.report/CVE-2026-8636","api":"https://cve.report/api/cve/CVE-2026-8636.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-8636","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-8636"},"summary":{"title":"Multiple Vulnerabilities in IBM Datacap","description":"IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 allows an attacker to retrieve user passwords and cryptographic keys from memory. Attacker can use the same keys to decrypt password, gain access to the application and access sensitive data in the database.","state":"PUBLISHED","assigner":"ibm","published_at":"2026-06-22 16:16:42","updated_at":"2026-06-22 18:16:51"},"problem_types":["CWE-316","CWE-316 CWE-316 Cleartext Storage of Sensitive Information in Memory"],"metrics":[{"version":"3.1","source":"psirt@us.ibm.com","type":"Secondary","score":"5.5","severity":"MEDIUM","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":5.5,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"}},{"version":"3.1","source":"CNA","type":"CVSS","score":"5.5","severity":"MEDIUM","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","data":{"attackComplexity":"LOW","attackVector":"LOCAL","availabilityImpact":"NONE","baseScore":5.5,"baseSeverity":"MEDIUM","confidentialityImpact":"HIGH","integrityImpact":"NONE","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","version":"3.1"}}],"references":[{"url":"https://www.ibm.com/support/pages/node/7276609","name":"https://www.ibm.com/support/pages/node/7276609","refsource":"psirt@us.ibm.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-8636","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-8636","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"IBM","product":"Datacap","version":"affected 9.1.7 1.8.4 semver","platforms":[]},{"source":"CNA","vendor":"IBM","product":"Datacap","version":"affected 9.1.8","platforms":[]},{"source":"CNA","vendor":"IBM","product":"Datacap","version":"affected 9.1.9","platforms":[]},{"source":"CNA","vendor":"IBM","product":"Datacap Navigator","version":"affected 9.1.7 8.2.1.0 semver","platforms":[]},{"source":"CNA","vendor":"IBM","product":"Datacap Navigator","version":"affected 9.1.8","platforms":[]},{"source":"CNA","vendor":"IBM","product":"Datacap Navigator","version":"affected 9.1.9","platforms":[]}],"timeline":[],"solutions":[{"source":"CNA","title":"","value":"IBM strongly suggests that you address the vulnerabilities now for all affected products/versions listed above by installing IBM Datacap 9.1.9 Interim Fix 008","time":"","lang":"en"}],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2026-8636","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","timestamp":"2026-06-22T16:07:01.577649Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-06-22T16:07:09.938Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"cpes":["cpe:2.3:a:ibm:datacap:9.1.7:*:*:*:*:*:*:*","cpe:2.3:a:ibm:datacap:9.1.8:*:*:*:*:*:*:*","cpe:2.3:a:ibm:datacap:9.1.9:*:*:*:*:*:*:*"],"product":"Datacap","vendor":"IBM","versions":[{"lessThanOrEqual":"1.8.4","status":"affected","version":"9.1.7","versionType":"semver"},{"status":"affected","version":"9.1.8"},{"status":"affected","version":"9.1.9"}]},{"cpes":["cpe:2.3:a:ibm:datacap_navigator:9.1.7:*:*:*:*:*:*:*","cpe:2.3:a:ibm:datacap_navigator:9.1.8:*:*:*:*:*:*:*","cpe:2.3:a:ibm:datacap_navigator:9.1.9:*:*:*:*:*:*:*"],"product":"Datacap Navigator","vendor":"IBM","versions":[{"lessThanOrEqual":"8.2.1.0","status":"affected","version":"9.1.7","versionType":"semver"},{"status":"affected","version":"9.1.8"},{"status":"affected","version":"9.1.9"}]}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 allows an attacker to retrieve user passwords and cryptographic keys from memory. Attacker can&nbsp;use the same keys to decrypt password, gain access to the application and access sensitive&nbsp;data in the database.</p>"}],"value":"IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 allows an attacker to retrieve user passwords and cryptographic keys from memory. Attacker can use the same keys to decrypt password, gain access to the application and access sensitive data in the database."}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"LOCAL","availabilityImpact":"NONE","baseScore":5.5,"baseSeverity":"MEDIUM","confidentialityImpact":"HIGH","integrityImpact":"NONE","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-316","description":"CWE-316 Cleartext Storage of Sensitive Information in Memory","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-06-22T14:16:01.647Z","orgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","shortName":"ibm"},"references":[{"tags":["vendor-advisory","patch"],"url":"https://www.ibm.com/support/pages/node/7276609"}],"solutions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>IBM strongly suggests that you address the vulnerabilities now for all affected products/versions listed above by installing <a href=\"https://www.ibm.com/support/pages/ibm-datacap-version-919-interim-fix-008-readme-file\" rel=\"nofollow\">IBM Datacap 9.1.9 Interim Fix 008</a></p>"}],"value":"IBM strongly suggests that you address the vulnerabilities now for all affected products/versions listed above by installing IBM Datacap 9.1.9 Interim Fix 008"}],"title":"Multiple Vulnerabilities in IBM Datacap","x_generator":{"engine":"ibm-cvegen"}}},"cveMetadata":{"assignerOrgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","assignerShortName":"ibm","cveId":"CVE-2026-8636","datePublished":"2026-06-22T14:16:01.647Z","dateReserved":"2026-05-14T19:33:49.373Z","dateUpdated":"2026-06-22T16:07:09.938Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-06-22 16:16:42","lastModifiedDate":"2026-06-22 18:16:51","problem_types":["CWE-316","CWE-316 CWE-316 Cleartext Storage of Sensitive Information in Memory"],"metrics":{"cvssMetricV31":[{"source":"psirt@us.ibm.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":5.5,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-06-22T16:07:01.577649Z","id":"CVE-2026-8636","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"8636","Ordinal":"1","Title":"Multiple Vulnerabilities in IBM Datacap","CVE":"CVE-2026-8636","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"8636","Ordinal":"1","NoteData":"IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 allows an attacker to retrieve user passwords and cryptographic keys from memory. Attacker can use the same keys to decrypt password, gain access to the application and access sensitive data in the database.","Type":"Description","Title":"Multiple Vulnerabilities in IBM Datacap"}]}}}