CVE-2014-0894

low
Published 2014-07-07 · Modified 2026-05-06
CVSS v3
CVSS v2
3.5
VIR risk
3.5

Description

RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics allows context-dependent attackers to discover database credentials by reading the DbUser and DbPass fields in an XML document.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: psirt@us.ibm.com — http://www-01.ibm.com/support/docview.wss?uid=swg21675881

Application impact

VendorProductVersionsFixed
ibmalgo_credit_limits4.5.0
ibmalgo_credit_limits4.7.0
ibmalgorithmics-

References

CWEs

CWE-200

Verify integrity in audit chain (admin only). AS-IS.