CVE-2026-8636
MEDIUM
5.5
CVSS 3.1
Description
IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 allows an attacker to retrieve user passwords and cryptographic keys from memory. Attacker can use the same keys to decrypt password, gain access to the application and access sensitive data in the database.
Metadata
Severity & Metrics
5.5
MEDIUM CVSS 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
SSVC — CISA Coordinator
Affected products (2)
| Vendor | Product | Platform | Versions |
|---|---|---|---|
| IBM | Datacap | — | 9.1.7 ≤ 1.8.4, 9.1.8, 9.1.9 |
| IBM | Datacap Navigator | — | 9.1.7 ≤ 8.2.1.0, 9.1.8, 9.1.9 |
Weakness (CWE)
| CWE | Source | Description |
|---|---|---|
| CWE-316 | cna | CWE-316 Cleartext Storage of Sensitive Information in Memory |
CVSS scores (1)
| Score | Severity | Version | Source | Vector |
|---|---|---|---|---|
| 5.5 | MEDIUM | 3.1 | cna | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
References (1)