CVE-2020-4328SQL Injection in IBM Financial Transaction Manager

CWE-89SQL Injection3 documents3 sources
Severity
6.3MEDIUMNVD
EPSS
0.2%
top 56.66%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 3
Latest updateMay 24

Description

IBM Financial Transaction Manager 3.2.4 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 177839.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:LExploitability: 2.8 | Impact: 3.4

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-qg5g-q63w-qf8c: IBM Financial Transaction Manager 32022-05-24
CVEList
CVE-2020-4328: IBM Financial Transaction Manager 32020-08-03
CVE-2020-4328 — SQL Injection in IBM | cvebase