CVE-2026-8636 PUBLISHED

Multiple Vulnerabilities in IBM Datacap

Assigner: ibm
Reserved: 14.05.2026 Published: 22.06.2026 Updated: 22.06.2026

IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 allows an attacker to retrieve user passwords and cryptographic keys from memory. Attacker can use the same keys to decrypt password, gain access to the application and access sensitive data in the database.

Metrics

CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS Score: 5.5

Product Status

Vendor IBM
Product Datacap
Versions
  • affected from 9.1.7 to 1.8.4 (incl.)
  • Version 9.1.8 is affected
  • Version 9.1.9 is affected
Vendor IBM
Product Datacap Navigator
Versions
  • affected from 9.1.7 to 8.2.1.0 (incl.)
  • Version 9.1.8 is affected
  • Version 9.1.9 is affected

Solutions

IBM strongly suggests that you address the vulnerabilities now for all affected products/versions listed above by installing IBM Datacap 9.1.9 Interim Fix 008

References

Problem Types

  • CWE-316 Cleartext Storage of Sensitive Information in Memory CWE