Show filters
60 Total Results
Displaying 51-60 of 60
Sort by:
Attacker Value
Unknown
CVE-2017-1152
Disclosure Date: April 14, 2017 (last updated November 26, 2024)
IBM Financial Transaction Manager 3.0.1 and 3.0.2 does not properly update the SESSIONID with each request, which could allow a user to obtain the ID in further attacks against the system. IBM X-Force ID: 122293.
0
Attacker Value
Unknown
CVE-2016-5920
Disclosure Date: October 29, 2016 (last updated November 25, 2024)
Cross-site scripting (XSS) vulnerability in the Web UI in IBM Financial Transaction Manager (FTM) for ACH Services 3.0.0.x before fp0015 and 3.0.1.0 before iFix0002 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown
CVE-2016-3060
Disclosure Date: October 29, 2016 (last updated November 25, 2024)
Payments Director in IBM Financial Transaction Manager (FTM) for ACH Services, Check Services, and Corporate Payment Services (CPS) 3.0.0.x before fp0015 and 3.0.1.0 before iFix0002 allows remote authenticated users to conduct clickjacking attacks via a crafted web site.
0
Attacker Value
Unknown
CVE-2016-0232
Disclosure Date: February 15, 2016 (last updated November 25, 2024)
IBM Financial Transaction Manager (FTM) for ACH Services, Check Services and Corporate Payment Services (CPS) 3.0.0 before FP12 allows remote authenticated users to obtain sensitive information by reading README files.
0
Attacker Value
Unknown
CVE-2016-0231
Disclosure Date: February 15, 2016 (last updated November 25, 2024)
IBM Financial Transaction Manager (FTM) for ACH Services, Check Services and Corporate Payment Services (CPS) 3.0.0 before FP12 allows remote authenticated users to obtain sensitive information by reading exception details in error logs.
0
Attacker Value
Unknown
CVE-2014-8917
Disclosure Date: January 28, 2015 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in (1) dojox/form/resources/uploader.swf (aka upload.swf), (2) dojox/form/resources/fileuploader.swf (aka fileupload.swf), (3) dojox/av/resources/audio.swf, and (4) dojox/av/resources/video.swf in the IBM Dojo Toolkit, as used in IBM Social Media Analytics 1.3 before IF11 and other products, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown
CVE-2014-0832
Disclosure Date: February 01, 2014 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in configuration-details screens in the OAC component in IBM Financial Transaction Manager (FTM) 2.0 before 2.0.0.3 allow remote authenticated users to inject arbitrary web script or HTML via a crafted text value.
0
Attacker Value
Unknown
CVE-2014-0833
Disclosure Date: February 01, 2014 (last updated October 05, 2023)
The OAC component in IBM Financial Transaction Manager (FTM) 2.0 before 2.0.0.3 does not properly enforce operator-intervention requirements, which allows remote authenticated users to bypass intended access restrictions via an unspecified process step.
0
Attacker Value
Unknown
CVE-2014-0831
Disclosure Date: February 01, 2014 (last updated October 05, 2023)
Cross-site request forgery (CSRF) vulnerability in the OAC component in IBM Financial Transaction Manager (FTM) 2.0 before 2.0.0.3 allows remote attackers to hijack the authentication of arbitrary users for requests that modify configuration data.
0
Attacker Value
Unknown
CVE-2014-0830
Disclosure Date: February 01, 2014 (last updated October 05, 2023)
Directory traversal vulnerability in the table-export implementation in the OAC component in IBM Financial Transaction Manager (FTM) 2.0 before 2.0.0.3 and 2.1 before 2.1.0.1 allows remote authenticated users to read arbitrary files via a modified pathname.
0