HTTP: IBM Algorithmics RICOS Password Disclosure

This signature detects attempts to exploit a known vulnerability in the IBM Algorithmics RICOS. Successful attack allows context-dependent attackers to discover database credentials by reading the DbUser and DbPass fields in an XML document.

Extended Description

RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics allows context-dependent attackers to discover database credentials by reading the DbUser and DbPass fields in an XML document.

Affected Products

Ibm algorithmics

References

CVE: CVE-2014-0894

Short Name
HTTP:IBM-ACLM-PD
Severity
Minor
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
Algorithmics CVE-2014-0894 Disclosure IBM Password RICOS
Release Date
05/15/2017
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3761
False Positive
Unknown
Vendors

Ibm

CVSS Score

3.5

Found a potential security threat?