Executive brief
IBM Datacap, a platform used for automated data capture and document processing, contains a security flaw that could allow an authorized user on the system to extract sensitive information from the computer's memory. Specifically, an attacker could retrieve user passwords and the cryptographic keys used to protect them. This could lead to unauthorized access to the application and the sensitive business data stored within its database.
Technical details
IBM Datacap and Datacap Navigator are vulnerable to cleartext storage of sensitive information in memory (CWE-316). A local attacker with low-level privileges can exploit this to retrieve user passwords and the cryptographic keys used for their encryption. By obtaining these keys, the attacker can decrypt stored passwords, gain unauthorized access to the Datacap application, and subsequently access sensitive data within the backend database. The vulnerability is addressed in IBM Datacap version 9.1.9 Interim Fix 008.
Affected products
- IBM Datacap 9.1.7, 9.1.8, 9.1.9
- IBM Datacap Navigator 9.1.7, 9.1.8, 9.1.9
Timeline
- 2026-06-16: advisory: Initial publication by IBM
- 2026-06-22: disclosed: NVD publication date