The decrypt function in RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics does not require a key, which makes it easier for remote attackers to obtain cleartext passwords by sniffing the network and then providing a string argument to this function.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Algo_credit_limits | Ibm | 4.5.0 (including) | 4.5.0 (including) |
Algo_credit_limits | Ibm | 4.7.0 (including) | 4.7.0 (including) |
Algorithmics | Ibm | - (including) | - (including) |