Back to overview

CVE-2026-8636

MEDIUM
5.5
CVSS 3.1
Description
IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 allows an attacker to retrieve user passwords and cryptographic keys from memory. Attacker can use the same keys to decrypt password, gain access to the application and access sensitive data in the database.

Metadata

CVE ID
CVE-2026-8636
State
PUBLISHED
Assigner
ibm
Reserved
2026-05-14 19:33 UTC
Published
2026-06-22 14:16 UTC
Last updated
2026-06-22 16:07 UTC
Primary CWE
CWE-316
CWE-316 Cleartext Storage of Sensitive Information in Memory
Vendor / Product
IBM / Datacap
Sources
cve.org  ·  NVD

Severity & Metrics

5.5 MEDIUM CVSS 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
SSVC — CISA Coordinator
Exploitation
none
Automatable
no
Tech. Impact
partial
Affected products (2)
VendorProductPlatformVersions
IBM Datacap 9.1.7 ≤ 1.8.4, 9.1.8, 9.1.9
IBM Datacap Navigator 9.1.7 ≤ 8.2.1.0, 9.1.8, 9.1.9
Weakness (CWE)
CWESourceDescription
CWE-316 cna CWE-316 Cleartext Storage of Sensitive Information in Memory
CVSS scores (1)
ScoreSeverityVersionSourceVector
5.5 MEDIUM 3.1 cna CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Back to overview