peter bassill · operator
$ cve CVE-2014-0864 JSON

CVE-2014-0864 EXPLOIT

6.8
MEDIUM · CVSS 2.0 · EPSS 2.5% (pctl 84)

Patch early

A public exploit exists.

Description

Multiple cross-site request forgery (CSRF) vulnerabilities in Executer in RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics allow remote attackers to hijack the authentication of arbitrary users for requests that change (1) a deal's currency or (2) a limit via a crafted XML document.

Scoring

CVSS6.8 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS2.52% — more likely to be exploited than 84% of all CVEs
WeaknessCWE-352
On CISA KEVno
Public exploityes
Published2014-07-07
Last modified2026-06-17

Affected (1)

VendorProduct
ibmalgo credit limits

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD