IBM Algo Credit Limits Plaintext Credentials Information Disclosure Vulnerability
BID:68269
Info
IBM Algo Credit Limits Plaintext Credentials Information Disclosure Vulnerability
| Bugtraq ID: | 68269 |
| Class: | Design Error |
| CVE: |
CVE-2014-0866 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 30 2014 12:00AM |
| Updated: | Jun 30 2014 12:00AM |
| Credit: | A. Kolmann, V. Habsburg-Lothringen, and F. Lukavsky of SEC Consult Vulnerability Lab. |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
IBM Algo Credit Limits Plaintext Credentials Information Disclosure Vulnerability
Algo Credit Limits is prone to an information-disclosure vulnerability.
Attackers can exploit this issue to gain access to the application credentials by sniffing network traffic through a man-in-the-middle attack. Successful exploits will lead to other attacks.
IBM Algo Credit Limits 4.5.0 through 4.7.0 are vulnerable; other versions may also be affected.
Algo Credit Limits is prone to an information-disclosure vulnerability.
Attackers can exploit this issue to gain access to the application credentials by sniffing network traffic through a man-in-the-middle attack. Successful exploits will lead to other attacks.
IBM Algo Credit Limits 4.5.0 through 4.7.0 are vulnerable; other versions may also be affected.
Exploit / POC
IBM Algo Credit Limits Plaintext Credentials Information Disclosure Vulnerability
An attacker may use readily available tools to exploit this issue.
An attacker may use readily available tools to exploit this issue.
Solution / Fix
IBM Algo Credit Limits Plaintext Credentials Information Disclosure Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
IBM Algo Credit Limits Plaintext Credentials Information Disclosure Vulnerability
References:
References:
- IBM Homepage (IBM)
- Multiple severe vulnerabilities (SEC Consult Vulnerability Lab)
- Security Bulletin: Multiple Security Vulnerabilities in Certain GUI Components o (IBM)