CVE-2020-5002
- EPSS 0.58%
- Veröffentlicht 10.03.2023 21:15:10
- Zuletzt bearbeitet 21.11.2024 05:33:32
IBM Financial Transaction Manager 3.2.0 through 3.2.10 could allow an authenticated user to perform unauthorized actions due to improper validation. IBM X-Force ID: 192954.
CVE-2020-5026
- EPSS 0.75%
- Veröffentlicht 01.03.2023 22:15:10
- Zuletzt bearbeitet 21.11.2024 05:33:34
IBM Financial Transaction Manager for Digital Payments for Multi-Platform 3.2.0 through 3.2.7 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be...
CVE-2020-5001
- EPSS 1.02%
- Veröffentlicht 01.03.2023 22:15:09
- Zuletzt bearbeitet 21.11.2024 05:33:32
IBM Financial Transaction Manager 3.2.0 through 3.2.7 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the sy...
CVE-2022-43875
- EPSS 0.18%
- Veröffentlicht 20.12.2022 19:15:25
- Zuletzt bearbeitet 21.11.2024 07:27:19
IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4 could allow an authenticated user to lock additional RM authorizations, resulting in a denial of service on displaying or managing these authorizations. IBM X-Force ID: 2...
CVE-2022-43872
- EPSS 0.49%
- Veröffentlicht 20.12.2022 19:15:24
- Zuletzt bearbeitet 21.11.2024 07:27:18
IBM Financial Transaction Manager 3.2.4 authorization checks are done incorrectly for some HTTP requests which allows getting unauthorized technical information (e.g. event log entries) about the FTM SWIFT system. IBM X-Force ID: 239708.
CVE-2019-4575
- EPSS 1.09%
- Veröffentlicht 15.06.2022 16:15:08
- Zuletzt bearbeitet 21.11.2024 04:43:45
IBM Financial Transaction Manager for Digital Payments for Multi-Platform 3.2.0 through 3.2.9 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete...
CVE-2021-39044
- EPSS 0.38%
- Veröffentlicht 02.02.2022 12:15:08
- Zuletzt bearbeitet 21.11.2024 06:18:28
IBM Financial Transaction Manager 3.2.4 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 214210.
CVE-2021-39066
- EPSS 0.64%
- Veröffentlicht 02.02.2022 12:15:08
- Zuletzt bearbeitet 21.11.2024 06:18:32
IBM Financial Transaction Manager 3.2.4 does not invalidate session any existing session identifier gives an attacker the opportunity to steal authenticated sessions. IBM X-Force ID: 215040.
CVE-2021-29841
- EPSS 0.5%
- Veröffentlicht 14.09.2021 14:15:10
- Zuletzt bearbeitet 21.11.2024 06:01:54
IBM Financial Transaction Manager 3.2.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure wit...
CVE-2020-5000
- EPSS 0.47%
- Veröffentlicht 15.06.2021 20:15:11
- Zuletzt bearbeitet 21.11.2024 05:33:31
IBM Financial Transaction Manager 3.2.0 through 3.2.8 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials ...