CVE-2020-5003
- EPSS 1.84%
- Veröffentlicht 11.06.2021 15:15:07
- Zuletzt bearbeitet 21.11.2024 05:33:32
IBM Financial Transaction Manager 3.2.4 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-For...
CVE-2020-4555
- EPSS 0.76%
- Veröffentlicht 21.12.2020 18:15:15
- Zuletzt bearbeitet 21.11.2024 05:32:53
IBM Financial Transaction Manager 3.0.6 and 3.1.0 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 183328.
CVE-2020-4560
- EPSS 0.85%
- Veröffentlicht 03.08.2020 13:15:12
- Zuletzt bearbeitet 21.11.2024 05:32:54
IBM Financial Transaction Manager 3.2.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure wit...
CVE-2018-1790
- EPSS 0.53%
- Veröffentlicht 10.05.2019 15:29:02
- Zuletzt bearbeitet 21.11.2024 04:00:22
IBM Financial Transaction Manager for Digital Payments for Multi-Platform 3.0.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. I...
CVE-2019-4032
- EPSS 1.55%
- Veröffentlicht 05.03.2019 18:29:00
- Zuletzt bearbeitet 21.11.2024 04:43:03
IBM Financial Transaction Manager for Digital Payments for Multi-Platform 3.1.0 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information i...
CVE-2018-2026
- EPSS 1.36%
- Veröffentlicht 23.01.2019 15:29:00
- Zuletzt bearbeitet 21.11.2024 04:03:36
IBM Financial Transaction Manager 3.2.1 for Digital Payments could allow an authenticated user to obtain a directory listing of internal product files. IBM X-Force ID: 155552.
CVE-2018-1871
- EPSS 0.97%
- Veröffentlicht 06.12.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 04:00:30
IBM Financial Transaction Manager for Digital Payments for Multi-Platform 3.0.0, 3.0.2, and 3.0.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended funct...
CVE-2018-1819
- EPSS 1.66%
- Veröffentlicht 04.10.2018 14:29:01
- Zuletzt bearbeitet 21.11.2024 04:00:27
IBM Financial Transaction Manager for Digital Payments for Multi-Platform 3.0.2, 3.0.4, 3.0.6, and 3.2.0 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modif...
CVE-2018-1670
- EPSS 1.21%
- Veröffentlicht 04.10.2018 14:29:01
- Zuletzt bearbeitet 21.11.2024 04:00:10
IBM Financial Transaction Manager for ACH Services for Multi-Platform 3.0.2 could allow an authenticated user to obtain sensitive product configuration information from log files. IBM X-Force ID: 144946.
CVE-2018-1393
- EPSS 1.23%
- Veröffentlicht 13.06.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:59:44
IBM Financial Transaction Manager for ACH Services for Multi-Platform 3.0.6 could allow an authenticated user to execute a specially crafted command that could obtain sensitive information. IBM X-Force ID: 138378.