CVE-2026-8636 Details
Description
IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 allows an attacker to retrieve user passwords and cryptographic keys from memory. Attacker can use the same keys to decrypt password, gain access to the application and access sensitive data in the database.
A vulnerability in IBM Datacap versions 9.1.7, 9.1.8, and 9.1.9, as well as in IBM Datacap Navigator versions 9.1.7, 9.1.8, and 9.1.9, allows attackers to extract user passwords and cryptographic keys from memory. The extracted keys can be used to decrypt passwords, gain access to the application, and retrieve sensitive data from the database.
Users are advised to upgrade to IBM Datacap version 9.1.9 Interim Fix 008, which addresses this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 22, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.ibm.com/support/pages/node/7276609 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-316 | Cleartext Storage of Sensitive Information in Memory | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| ibm datacap | 9.1.7 9.1.8 9.1.9 |
CPE
Remediation
| |
| ibm datacap navigator | 9.1.7 9.1.8 9.1.9 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 26, 2026 | Initial Analysis | [email protected] |
| Jun 22, 2026 | CVE Modified | CISA-ADP |
| Jun 22, 2026 | New CVE Received | [email protected] |