HTTP: IBM Algo Credit Limits CVE-2014-0867 Security Bypass

This signature detects attempts to exploit a known vulnerability against IBM. A successful exploit can result in a sensitive data modification.

Extended Description

rcore6/main/addcookie.jsp in RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics allows remote attackers to create or modify cookies via the query string.

Affected Products

Ibm algorithmics

References

BugTraq: 68266

CVE: CVE-2014-0867

Short Name
HTTP:MISC:IBM-CRDIT-LMT-BYPAS
Severity
Minor
Recommended
True
Recommended Action
Drop
Category
HTTP
Keywords
Algo Bypass CVE-2014-0867 Credit IBM Limits Security bid:68266
Release Date
02/04/2015
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3761
False Positive
Unknown
Vendors

Ibm

CVSS Score

5.8

Found a potential security threat?