5.7

CVE-2016-3060

Payments Director in IBM Financial Transaction Manager (FTM) for ACH Services, Check Services, and Corporate Payment Services (CPS) 3.0.0.x before fp0015 and 3.0.1.0 before iFix0002 allows remote authenticated users to conduct clickjacking attacks via a crafted web site.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
IbmFinancial Transaction Manager Version3.0.0.0 SwPlatformcps_services
IbmFinancial Transaction Manager Version3.0.0.1 SwPlatformcps_services
IbmFinancial Transaction Manager Version3.0.0.2 SwPlatformcps_services
IbmFinancial Transaction Manager Version3.0.0.3 SwPlatformcps_services
IbmFinancial Transaction Manager Version3.0.0.4 SwPlatformcps_services
IbmFinancial Transaction Manager Version3.0.0.5 SwPlatformcps_services
IbmFinancial Transaction Manager Version3.0.0.6 SwPlatformcps_services
IbmFinancial Transaction Manager Version3.0.0.7 SwPlatformcps_services
IbmFinancial Transaction Manager Version3.0.0.8 SwPlatformcps_services
IbmFinancial Transaction Manager Version3.0.0.9 SwPlatformcps_services
IbmFinancial Transaction Manager Version3.0.0.10 SwPlatformcps_services
IbmFinancial Transaction Manager Version3.0.0.11 SwPlatformcps_services
IbmFinancial Transaction Manager Version3.0.0.12 SwPlatformcps_services
IbmFinancial Transaction Manager Version3.0.0.13 SwPlatformcps_services
IbmFinancial Transaction Manager Version3.0.0.14 SwPlatformcps_services
IbmFinancial Transaction Manager Version3.0.0.0 SwPlatformach_services
IbmFinancial Transaction Manager Version3.0.0.1 SwPlatformach_services
IbmFinancial Transaction Manager Version3.0.0.2 SwPlatformach_services
IbmFinancial Transaction Manager Version3.0.0.3 SwPlatformach_services
IbmFinancial Transaction Manager Version3.0.0.4 SwPlatformach_services
IbmFinancial Transaction Manager Version3.0.0.5 SwPlatformach_services
IbmFinancial Transaction Manager Version3.0.0.6 SwPlatformach_services
IbmFinancial Transaction Manager Version3.0.0.7 SwPlatformach_services
IbmFinancial Transaction Manager Version3.0.0.8 SwPlatformach_services
IbmFinancial Transaction Manager Version3.0.0.9 SwPlatformach_services
IbmFinancial Transaction Manager Version3.0.0.10 SwPlatformach_services
IbmFinancial Transaction Manager Version3.0.0.11 SwPlatformach_services
IbmFinancial Transaction Manager Version3.0.0.12 SwPlatformach_services
IbmFinancial Transaction Manager Version3.0.0.13 SwPlatformach_services
IbmFinancial Transaction Manager Version3.0.0.14 SwPlatformach_services
IbmFinancial Transaction Manager Version3.0.1.0 SwPlatformach_services
IbmFinancial Transaction Manager Version3.0.0.0 SwPlatformcheck_services
IbmFinancial Transaction Manager Version3.0.0.1 SwPlatformcheck_services
IbmFinancial Transaction Manager Version3.0.0.2 SwPlatformcheck_services
IbmFinancial Transaction Manager Version3.0.0.3 SwPlatformcheck_services
IbmFinancial Transaction Manager Version3.0.0.4 SwPlatformcheck_services
IbmFinancial Transaction Manager Version3.0.0.5 SwPlatformcheck_services
IbmFinancial Transaction Manager Version3.0.0.6 SwPlatformcheck_services
IbmFinancial Transaction Manager Version3.0.0.7 SwPlatformcheck_services
IbmFinancial Transaction Manager Version3.0.0.8 SwPlatformcheck_services
IbmFinancial Transaction Manager Version3.0.0.9 SwPlatformcheck_services
IbmFinancial Transaction Manager Version3.0.0.10 SwPlatformcheck_services
IbmFinancial Transaction Manager Version3.0.0.11 SwPlatformcheck_services
IbmFinancial Transaction Manager Version3.0.0.12 SwPlatformcheck_services
IbmFinancial Transaction Manager Version3.0.0.13 SwPlatformcheck_services
IbmFinancial Transaction Manager Version3.0.0.14 SwPlatformcheck_services
IbmFinancial Transaction Manager Version3.0.1.0 SwPlatformcheck_services
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.16% 0.336
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.7 2.1 3.6
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N
nvd@nist.gov 3.5 6.8 2.9
AV:N/AC:M/Au:S/C:N/I:P/A:N
CWE-284 Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.