CVE-2017-1606
- EPSS 1.44%
- Veröffentlicht 11.12.2017 21:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
IBM Financial Transaction Manager (FTM) for Multi-Platform (MP) 3.0.0.0 through 3.0.0.7 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete infor...
CVE-2017-1538
- EPSS 1.39%
- Veröffentlicht 10.10.2017 21:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
IBM Financial Transaction Manager for ACH Services for Multi-Platform 3.0.2 could allow an authenticated user to obtain sensitive information from an undocumented URL. IBM X-Force ID: 130735.
CVE-2017-1160
- EPSS 0.54%
- Veröffentlicht 17.04.2017 21:59:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
IBM Financial Transaction Manager for ACH Services for Multi-Platform 3.0.0.x is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially...
CVE-2017-1152
- EPSS 0.6%
- Veröffentlicht 14.04.2017 16:59:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
IBM Financial Transaction Manager 3.0.1 and 3.0.2 does not properly update the SESSIONID with each request, which could allow a user to obtain the ID in further attacks against the system. IBM X-Force ID: 122293.
CVE-2016-5920
- EPSS 0.8%
- Veröffentlicht 29.10.2016 01:59:35
- Zuletzt bearbeitet 06.05.2026 22:30:45
Cross-site scripting (XSS) vulnerability in the Web UI in IBM Financial Transaction Manager (FTM) for ACH Services 3.0.0.x before fp0015 and 3.0.1.0 before iFix0002 allows remote authenticated users to inject arbitrary web script or HTML via unspecif...
CVE-2016-3060
- EPSS 0.8%
- Veröffentlicht 29.10.2016 01:59:12
- Zuletzt bearbeitet 06.05.2026 22:30:45
Payments Director in IBM Financial Transaction Manager (FTM) for ACH Services, Check Services, and Corporate Payment Services (CPS) 3.0.0.x before fp0015 and 3.0.1.0 before iFix0002 allows remote authenticated users to conduct clickjacking attacks vi...
CVE-2016-0232
- EPSS 1.13%
- Veröffentlicht 15.02.2016 23:59:01
- Zuletzt bearbeitet 06.05.2026 22:30:45
IBM Financial Transaction Manager (FTM) for ACH Services, Check Services and Corporate Payment Services (CPS) 3.0.0 before FP12 allows remote authenticated users to obtain sensitive information by reading README files.
CVE-2016-0231
- EPSS 1.13%
- Veröffentlicht 15.02.2016 23:59:00
- Zuletzt bearbeitet 06.05.2026 22:30:45
IBM Financial Transaction Manager (FTM) for ACH Services, Check Services and Corporate Payment Services (CPS) 3.0.0 before FP12 allows remote authenticated users to obtain sensitive information by reading exception details in error logs.
CVE-2014-8917
- EPSS 2.06%
- Veröffentlicht 28.01.2015 22:59:00
- Zuletzt bearbeitet 06.05.2026 22:30:45
Multiple cross-site scripting (XSS) vulnerabilities in (1) dojox/form/resources/uploader.swf (aka upload.swf), (2) dojox/form/resources/fileuploader.swf (aka fileupload.swf), (3) dojox/av/resources/audio.swf, and (4) dojox/av/resources/video.swf in t...
- EPSS 1.44%
- Veröffentlicht 01.02.2014 15:55:04
- Zuletzt bearbeitet 29.04.2026 01:13:23
Directory traversal vulnerability in the table-export implementation in the OAC component in IBM Financial Transaction Manager (FTM) 2.0 before 2.0.0.3 and 2.1 before 2.1.0.1 allows remote authenticated users to read arbitrary files via a modified pa...