Show filters
338 Total Results
Displaying 31-40 of 338
Sort by:
Attacker Value
Unknown
CVE-2020-5001
Disclosure Date: March 01, 2023 (last updated November 08, 2023)
IBM Financial Transaction Manager 3.2.0 through 3.2.7 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 192953.
0
Attacker Value
Unknown
CVE-2022-43875
Disclosure Date: December 20, 2022 (last updated November 08, 2023)
IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4 could allow an authenticated user to lock additional RM authorizations, resulting in a denial of service on displaying or managing these authorizations. IBM X-Force ID: 240034.
0
Attacker Value
Unknown
CVE-2022-43872
Disclosure Date: December 20, 2022 (last updated November 08, 2023)
IBM Financial Transaction Manager 3.2.4 authorization checks are done incorrectly for some HTTP requests which allows getting unauthorized technical information (e.g. event log entries) about the FTM SWIFT system. IBM X-Force ID: 239708.
0
Attacker Value
Unknown
CVE-2022-41260
Disclosure Date: November 08, 2022 (last updated November 08, 2023)
SAP Financial Consolidation - version 1010, does not sufficiently encode user-controlled input which may allow an unauthenticated attacker to inject a web script via a GET request. On successful exploitation, an attacker can view or modify information causing a limited impact on confidentiality and integrity of the application.
0
Attacker Value
Unknown
CVE-2022-41208
Disclosure Date: November 08, 2022 (last updated November 08, 2023)
Due to insufficient input validation, SAP Financial Consolidation - version 1010, allows an authenticated attacker with user privileges to alter current user session. On successful exploitation, the attacker can view or modify information, causing a limited impact on confidentiality and integrity of the application.
0
Attacker Value
Unknown
CVE-2022-41258
Disclosure Date: November 08, 2022 (last updated November 08, 2023)
Due to insufficient input validation, SAP Financial Consolidation - version 1010, allows an authenticated attacker to inject malicious script when running a common query in the Web Administration Console. On successful exploitation, an attacker can view or modify information causing a limited impact on confidentiality, integrity and availability of the application.
0
Attacker Value
Unknown
CVE-2022-21580
Disclosure Date: July 19, 2022 (last updated December 22, 2024)
Vulnerability in the Oracle Financial Services Revenue Management and Billing product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 2.9.0.0.0, 2.9.0.1.0, 3.0.0.0.0-3.2.0.0.0 and 4.0.0.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financial Services Revenue Management and Billing. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Financial Services Revenue Management and Billing accessible data as well as unauthorized update, insert or delete access to some of Oracle Financial Services Revenue Management and Billing accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Financial Services Revenue Management and Billing. CVSS 3.1 Base Score 5.9 (…
0
Attacker Value
Unknown
CVE-2022-31589
Disclosure Date: June 14, 2022 (last updated February 23, 2025)
Due to improper authorization check, business users who are using Israeli File from SHAAM program (/ATL/VQ23 transaction), are granted more than needed authorization to perform certain transaction, which may lead to users getting access to data that would otherwise be restricted.
0
Attacker Value
Unknown
CVE-2019-4575
Disclosure Date: June 14, 2022 (last updated February 23, 2025)
IBM Financial Transaction Manager for Digital Payments for Multi-Platform 3.2.0 through 3.2.9 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 166801.
0
Attacker Value
Unknown
CVE-2022-22978
Disclosure Date: May 19, 2022 (last updated February 23, 2025)
In spring security versions prior to 5.4.11+, 5.5.7+ , 5.6.4+ and older unsupported versions, RegexRequestMatcher can easily be misconfigured to be bypassed on some servlet containers. Applications using RegexRequestMatcher with `.` in the regular expression are possibly vulnerable to an authorization bypass.
0