Show filters
18 Total Results
Displaying 1-10 of 18
Sort by:
Attacker Value
Unknown

CVE-2023-49880

Disclosure Date: December 25, 2023 (last updated January 04, 2024)
In the Message Entry and Repair (MER) facility of IBM Financial Transaction Manager for SWIFT Services 3.2.4 the sending address and the message type of FIN messages are assumed to be immutable. However, an attacker might modify these elements of a business transaction. IBM X-Force ID: 273183.
Attacker Value
Unknown

CVE-2023-35892

Disclosure Date: September 05, 2023 (last updated October 08, 2023)
IBM Financial Transaction Manager for SWIFT Services 3.2.4 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 258786.
Attacker Value
Unknown

CVE-2022-43871

Disclosure Date: April 29, 2023 (last updated October 08, 2023)
IBM Financial Transaction Manager for SWIFT Services 3.2.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 239707.
Attacker Value
Unknown

CVE-2022-43875

Disclosure Date: December 20, 2022 (last updated November 08, 2023)
IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4 could allow an authenticated user to lock additional RM authorizations, resulting in a denial of service on displaying or managing these authorizations. IBM X-Force ID: 240034.
Attacker Value
Unknown

CVE-2022-43872

Disclosure Date: December 20, 2022 (last updated November 08, 2023)
IBM Financial Transaction Manager 3.2.4 authorization checks are done incorrectly for some HTTP requests which allows getting unauthorized technical information (e.g. event log entries) about the FTM SWIFT system. IBM X-Force ID: 239708.
Attacker Value
Unknown

CVE-2021-39044

Disclosure Date: January 31, 2022 (last updated October 07, 2023)
IBM Financial Transaction Manager 3.2.4 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 214210.
Attacker Value
Unknown

CVE-2021-39066

Disclosure Date: January 31, 2022 (last updated October 07, 2023)
IBM Financial Transaction Manager 3.2.4 does not invalidate session any existing session identifier gives an attacker the opportunity to steal authenticated sessions. IBM X-Force ID: 215040.
Attacker Value
Unknown

CVE-2021-29841

Disclosure Date: September 13, 2021 (last updated November 28, 2024)
IBM Financial Transaction Manager 3.2.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 205045.
Attacker Value
Unknown

CVE-2020-5000

Disclosure Date: June 14, 2021 (last updated September 17, 2024)
IBM Financial Transaction Manager 3.2.0 through 3.2.8 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 192952.
Attacker Value
Unknown

CVE-2020-5003

Disclosure Date: June 10, 2021 (last updated November 28, 2024)
IBM Financial Transaction Manager 3.2.4 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 192956.