2026-06-22 14:16CVE-2026-8636ibm
PUBLISHED5.2ApplicationCWE-316

Multiple Vulnerabilities in IBM Datacap

IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 allows an attacker to retrieve user passwords and cryptographic keys from memory. Attacker can use the same keys to decrypt password, gain access to the application and access sensitive data in the database.

Problem type

Affected products

IBM

Datacap

<= 1.8.4 - AFFECTED

9.1.8 - AFFECTED

9.1.9 - AFFECTED

Datacap Navigator

<= 8.2.1.0 - AFFECTED

9.1.8 - AFFECTED

9.1.9 - AFFECTED

References

GitHub Security Advisories

GHSA-xfpj-q55p-7h2m

IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 allows an...

https://github.com/advisories/GHSA-xfpj-q55p-7h2m

IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 allows an attacker to retrieve user passwords and cryptographic keys from memory. Attacker can use the same keys to decrypt password, gain access to the application and access sensitive data in the database.

JSON source

https://cveawg.mitre.org/api/cve/CVE-2026-8636
Click to expand
{
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "cveMetadata": {
    "cveId": "CVE-2026-8636",
    "assignerOrgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
    "assignerShortName": "ibm",
    "dateUpdated": "2026-06-22T16:07:09.938Z",
    "dateReserved": "2026-05-14T19:33:49.373Z",
    "datePublished": "2026-06-22T14:16:01.647Z",
    "state": "PUBLISHED"
  },
  "containers": {
    "cna": {
      "providerMetadata": {
        "orgId": "9a959283-ebb5-44b6-b705-dcc2bbced522",
        "shortName": "ibm",
        "dateUpdated": "2026-06-22T14:16:01.647Z"
      },
      "title": "Multiple Vulnerabilities in IBM Datacap",
      "descriptions": [
        {
          "lang": "en",
          "value": "IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 allows an attacker to retrieve user passwords and cryptographic keys from memory. Attacker can use the same keys to decrypt password, gain access to the application and access sensitive data in the database.",
          "supportingMedia": [
            {
              "type": "text/html",
              "base64": false,
              "value": "<p>IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 allows an attacker to retrieve user passwords and cryptographic keys from memory. Attacker can&nbsp;use the same keys to decrypt password, gain access to the application and access sensitive&nbsp;data in the database.</p>"
            }
          ]
        }
      ],
      "affected": [
        {
          "vendor": "IBM",
          "product": "Datacap",
          "cpes": [
            "cpe:2.3:a:ibm:datacap:9.1.7:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:datacap:9.1.8:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:datacap:9.1.9:*:*:*:*:*:*:*"
          ],
          "versions": [
            {
              "version": "9.1.7",
              "status": "affected",
              "versionType": "semver",
              "lessThanOrEqual": "1.8.4"
            },
            {
              "version": "9.1.8",
              "status": "affected"
            },
            {
              "version": "9.1.9",
              "status": "affected"
            }
          ]
        },
        {
          "vendor": "IBM",
          "product": "Datacap Navigator",
          "cpes": [
            "cpe:2.3:a:ibm:datacap_navigator:9.1.7:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:datacap_navigator:9.1.8:*:*:*:*:*:*:*",
            "cpe:2.3:a:ibm:datacap_navigator:9.1.9:*:*:*:*:*:*:*"
          ],
          "versions": [
            {
              "version": "9.1.7",
              "status": "affected",
              "versionType": "semver",
              "lessThanOrEqual": "8.2.1.0"
            },
            {
              "version": "9.1.8",
              "status": "affected"
            },
            {
              "version": "9.1.9",
              "status": "affected"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "lang": "en",
              "description": "CWE-316 Cleartext Storage of Sensitive Information in Memory",
              "cweId": "CWE-316",
              "type": "CWE"
            }
          ]
        }
      ],
      "references": [
        {
          "url": "https://www.ibm.com/support/pages/node/7276609",
          "tags": [
            "vendor-advisory",
            "patch"
          ]
        }
      ],
      "metrics": [
        {
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ],
          "cvssV3_1": {
            "version": "3.1",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "scope": "UNCHANGED",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "NONE",
            "availabilityImpact": "NONE",
            "baseScore": 5.5,
            "baseSeverity": "MEDIUM"
          }
        }
      ],
      "solutions": [
        {
          "lang": "en",
          "value": "IBM strongly suggests that you address the vulnerabilities now for all affected products/versions listed above by installing IBM Datacap 9.1.9 Interim Fix 008",
          "supportingMedia": [
            {
              "type": "text/html",
              "base64": false,
              "value": "<p>IBM strongly suggests that you address the vulnerabilities now for all affected products/versions listed above by installing <a href=\"https://www.ibm.com/support/pages/ibm-datacap-version-919-interim-fix-008-readme-file\" rel=\"nofollow\">IBM Datacap 9.1.9 Interim Fix 008</a></p>"
            }
          ]
        }
      ]
    },
    "adp": [
      {
        "providerMetadata": {
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP",
          "dateUpdated": "2026-06-22T16:07:09.938Z"
        },
        "title": "CISA ADP Vulnrichment",
        "metrics": [
          {}
        ]
      }
    ]
  }
}