IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 allows an attacker to retrieve user passwords and cryptographic keys from memory. Attacker can use the same keys to decrypt password, gain access to the application and access sensitive data in the database.
PUBLISHED5.2ApplicationCWE-316
Multiple Vulnerabilities in IBM Datacap
Problem type
Affected products
IBM
Datacap
<= 1.8.4 - AFFECTED
9.1.8 - AFFECTED
9.1.9 - AFFECTED
Datacap Navigator
<= 8.2.1.0 - AFFECTED
9.1.8 - AFFECTED
9.1.9 - AFFECTED
References
GitHub Security Advisories
GHSA-xfpj-q55p-7h2m
IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 allows an...
https://github.com/advisories/GHSA-xfpj-q55p-7h2mIBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 allows an attacker to retrieve user passwords and cryptographic keys from memory. Attacker can use the same keys to decrypt password, gain access to the application and access sensitive data in the database.
JSON source
https://cveawg.mitre.org/api/cve/CVE-2026-8636Click to expand
{
"dataType": "CVE_RECORD",
"dataVersion": "5.2",
"cveMetadata": {
"cveId": "CVE-2026-8636",
"assignerOrgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
"assignerShortName": "ibm",
"dateUpdated": "2026-06-22T16:07:09.938Z",
"dateReserved": "2026-05-14T19:33:49.373Z",
"datePublished": "2026-06-22T14:16:01.647Z",
"state": "PUBLISHED"
},
"containers": {
"cna": {
"providerMetadata": {
"orgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
"shortName": "ibm",
"dateUpdated": "2026-06-22T14:16:01.647Z"
},
"title": "Multiple Vulnerabilities in IBM Datacap",
"descriptions": [
{
"lang": "en",
"value": "IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 allows an attacker to retrieve user passwords and cryptographic keys from memory. Attacker can use the same keys to decrypt password, gain access to the application and access sensitive data in the database.",
"supportingMedia": [
{
"type": "text/html",
"base64": false,
"value": "<p>IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 allows an attacker to retrieve user passwords and cryptographic keys from memory. Attacker can use the same keys to decrypt password, gain access to the application and access sensitive data in the database.</p>"
}
]
}
],
"affected": [
{
"vendor": "IBM",
"product": "Datacap",
"cpes": [
"cpe:2.3:a:ibm:datacap:9.1.7:*:*:*:*:*:*:*",
"cpe:2.3:a:ibm:datacap:9.1.8:*:*:*:*:*:*:*",
"cpe:2.3:a:ibm:datacap:9.1.9:*:*:*:*:*:*:*"
],
"versions": [
{
"version": "9.1.7",
"status": "affected",
"versionType": "semver",
"lessThanOrEqual": "1.8.4"
},
{
"version": "9.1.8",
"status": "affected"
},
{
"version": "9.1.9",
"status": "affected"
}
]
},
{
"vendor": "IBM",
"product": "Datacap Navigator",
"cpes": [
"cpe:2.3:a:ibm:datacap_navigator:9.1.7:*:*:*:*:*:*:*",
"cpe:2.3:a:ibm:datacap_navigator:9.1.8:*:*:*:*:*:*:*",
"cpe:2.3:a:ibm:datacap_navigator:9.1.9:*:*:*:*:*:*:*"
],
"versions": [
{
"version": "9.1.7",
"status": "affected",
"versionType": "semver",
"lessThanOrEqual": "8.2.1.0"
},
{
"version": "9.1.8",
"status": "affected"
},
{
"version": "9.1.9",
"status": "affected"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"lang": "en",
"description": "CWE-316 Cleartext Storage of Sensitive Information in Memory",
"cweId": "CWE-316",
"type": "CWE"
}
]
}
],
"references": [
{
"url": "https://www.ibm.com/support/pages/node/7276609",
"tags": [
"vendor-advisory",
"patch"
]
}
],
"metrics": [
{
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
],
"cvssV3_1": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
"attackVector": "LOCAL",
"attackComplexity": "LOW",
"privilegesRequired": "LOW",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"availabilityImpact": "NONE",
"baseScore": 5.5,
"baseSeverity": "MEDIUM"
}
}
],
"solutions": [
{
"lang": "en",
"value": "IBM strongly suggests that you address the vulnerabilities now for all affected products/versions listed above by installing IBM Datacap 9.1.9 Interim Fix 008",
"supportingMedia": [
{
"type": "text/html",
"base64": false,
"value": "<p>IBM strongly suggests that you address the vulnerabilities now for all affected products/versions listed above by installing <a href=\"https://www.ibm.com/support/pages/ibm-datacap-version-919-interim-fix-008-readme-file\" rel=\"nofollow\">IBM Datacap 9.1.9 Interim Fix 008</a></p>"
}
]
}
]
},
"adp": [
{
"providerMetadata": {
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP",
"dateUpdated": "2026-06-22T16:07:09.938Z"
},
"title": "CISA ADP Vulnrichment",
"metrics": [
{}
]
}
]
}
}