CVE-2014-0869: IBM Algo Credit Limits

Medium severity, CVSS 4.3. EPSS: 5.5% chance of exploitation in the next 30 days.

The decrypt function in RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics does not require a key, which makes it easier for remote attackers to obtain cleartext passwords by sniffing the network and then providing a string argument to this function.

Affected products

  • IBM Algo Credit Limits: version 4.5.0 only; version 4.7.0 only
  • IBM Algorithmics: affected versions not specified

Published 2014-07-07. Last modified 2026-06-17.