Show filters
18 Total Results
Displaying 1-10 of 18
Sort by:
Attacker Value
Unknown
CVE-2023-49880
Disclosure Date: December 25, 2023 (last updated January 04, 2024)
In the Message Entry and Repair (MER) facility of IBM Financial Transaction Manager for SWIFT Services 3.2.4 the sending address and the message type of FIN messages are assumed to be immutable. However, an attacker might modify these elements of a business transaction. IBM X-Force ID: 273183.
0
Attacker Value
Unknown
CVE-2023-35892
Disclosure Date: September 05, 2023 (last updated October 08, 2023)
IBM Financial Transaction Manager for SWIFT Services 3.2.4 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 258786.
0
Attacker Value
Unknown
CVE-2022-43871
Disclosure Date: April 29, 2023 (last updated October 08, 2023)
IBM Financial Transaction Manager for SWIFT Services 3.2.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 239707.
0
Attacker Value
Unknown
CVE-2022-43875
Disclosure Date: December 20, 2022 (last updated November 08, 2023)
IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4 could allow an authenticated user to lock additional RM authorizations, resulting in a denial of service on displaying or managing these authorizations. IBM X-Force ID: 240034.
0
Attacker Value
Unknown
CVE-2022-43872
Disclosure Date: December 20, 2022 (last updated November 08, 2023)
IBM Financial Transaction Manager 3.2.4 authorization checks are done incorrectly for some HTTP requests which allows getting unauthorized technical information (e.g. event log entries) about the FTM SWIFT system. IBM X-Force ID: 239708.
0
Attacker Value
Unknown
CVE-2021-39044
Disclosure Date: January 31, 2022 (last updated October 07, 2023)
IBM Financial Transaction Manager 3.2.4 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 214210.
0
Attacker Value
Unknown
CVE-2021-39066
Disclosure Date: January 31, 2022 (last updated October 07, 2023)
IBM Financial Transaction Manager 3.2.4 does not invalidate session any existing session identifier gives an attacker the opportunity to steal authenticated sessions. IBM X-Force ID: 215040.
0
Attacker Value
Unknown
CVE-2021-29841
Disclosure Date: September 13, 2021 (last updated November 28, 2024)
IBM Financial Transaction Manager 3.2.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 205045.
0
Attacker Value
Unknown
CVE-2020-5000
Disclosure Date: June 14, 2021 (last updated September 17, 2024)
IBM Financial Transaction Manager 3.2.0 through 3.2.8 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 192952.
0
Attacker Value
Unknown
CVE-2020-5003
Disclosure Date: June 10, 2021 (last updated November 28, 2024)
IBM Financial Transaction Manager 3.2.4 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 192956.
0