3.3

CVE-2016-0275

IBM Financial Transaction Manager (FTM) for ACH Services for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013, Financial Transaction Manager (FTM) for Check Services for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013, and Financial Transaction Manager (FTM) for Corporate Payment Services (CPS) for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013 allows local users to obtain sensitive information via vectors related to cacheable HTTPS responses.

Data is provided by the National Vulnerability Database (NVD)
IbmFinancial Transaction Manager SwPlatformach_services Version >= 3.0.0.0 <= 3.0.0.12
IbmFinancial Transaction Manager SwPlatformcheck_services Version >= 3.0.0.0 <= 3.0.0.12
IbmFinancial Transaction Manager SwPlatformcps_services Version >= 3.0.0.0 <= 3.0.0.12
IbmFinancial Transaction Manager Version2.1.1.2 SwPlatformach_services
IbmFinancial Transaction Manager Version2.1.1.2 SwPlatformcheck_services
IbmFinancial Transaction Manager Version2.1.1.2 SwPlatformcps_services
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.04% 0.099
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 3.3 1.8 1.4
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
nvd@nist.gov 2.1 3.9 2.9
AV:L/AC:L/Au:N/C:P/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.