Ibm Financial Transaction Manager vulnerabilities
57 known vulnerabilities affecting ibm/financial_transaction_manager.
Total CVEs
57
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH11MEDIUM37LOW5
Vulnerabilities
Page 2 of 3
CVE-2018-1391P4MEDIUMCVSS 6.5v3.0.4.0v3.1.0.0+2 more2018-02-22
CVE-2018-1391 [MEDIUM] CVE-2018-1391: IBM Financial Transaction Manager 3.0.4 and 3.1.0 for ACH Services for Multi-Platform could allow an
IBM Financial Transaction Manager 3.0.4 and 3.1.0 for ACH Services for Multi-Platform could allow an authenticated user to execute a specially crafted command that could cause a denial of service. IBM X-Force ID: 138376.
nvd
CVE-2014-0831P4MEDIUMCVSS 6.8v2.0.0.0v2.0.0.1+1 more2014-02-01
CVE-2014-0831 [MEDIUM] CWE-352 CVE-2014-0831: Cross-site request forgery (CSRF) vulnerability in the OAC component in IBM Financial Transaction Ma
Cross-site request forgery (CSRF) vulnerability in the OAC component in IBM Financial Transaction Manager (FTM) 2.0 before 2.0.0.3 allows remote attackers to hijack the authentication of arbitrary users for requests that modify configuration data.
nvd
CVE-2020-4905P4MEDIUMCVSS 5.9v3.2.42020-12-16
CVE-2020-4905 [MEDIUM] CVE-2020-4905: IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4 could allow an remote
IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4 could allow an remote attacker to obtain sensitive information, caused by a man in the middle attack. By SSL striping, an attacker could exploit this vulnerability to obtain sensitive information.
nvd
CVE-2020-4555P4MEDIUMCVSS 5.4v2.1.1.0v3.0.0+9 more2020-12-21
CVE-2020-4555 [MEDIUM] CWE-384 CVE-2020-4555: IBM Financial Transaction Manager 3.0.6 and 3.1.0 does not invalidate session after logout which cou
IBM Financial Transaction Manager 3.0.6 and 3.1.0 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 183328.
nvd
CVE-2019-4742P4MEDIUMCVSS 6.1v3.02019-12-20
CVE-2019-4742 [MEDIUM] CWE-1021 CVE-2019-4742: IBM Financial Transaction Manager 3.0 could allow a remote attacker to hijack the clicking action of
IBM Financial Transaction Manager 3.0 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 172877.
nvd
CVE-2014-0833P4MEDIUMCVSS 5.5v2.0.0.0v2.0.0.1+1 more2014-02-01
CVE-2014-0833 [MEDIUM] CWE-264 CVE-2014-0833: The OAC component in IBM Financial Transaction Manager (FTM) 2.0 before 2.0.0.3 does not properly en
The OAC component in IBM Financial Transaction Manager (FTM) 2.0 before 2.0.0.3 does not properly enforce operator-intervention requirements, which allows remote authenticated users to bypass intended access restrictions via an unspecified process step.
nvd
CVE-2022-43872P4MEDIUMCVSS 5.3v3.2.42022-12-20
CVE-2022-43872 [MEDIUM] CWE-863 CVE-2022-43872: IBM Financial Transaction Manager 3.2.4 authorization checks are done incorrectly for some HTTP req
IBM Financial Transaction Manager 3.2.4 authorization checks are done incorrectly for some HTTP requests which allows getting unauthorized technical information (e.g. event log entries) about the FTM SWIFT system. IBM X-Force ID: 239708.
nvd
CVE-2016-3060P4MEDIUMCVSS 5.7v3.0.0.0v3.0.0.1+14 more2016-10-29
CVE-2016-3060 [MEDIUM] CWE-284 CVE-2016-3060: Payments Director in IBM Financial Transaction Manager (FTM) for ACH Services, Check Services, and C
Payments Director in IBM Financial Transaction Manager (FTM) for ACH Services, Check Services, and Corporate Payment Services (CPS) 3.0.0.x before fp0015 and 3.0.1.0 before iFix0002 allows remote authenticated users to conduct clickjacking attacks via a crafted web site.
nvd
CVE-2016-0253P4MEDIUMCVSS 5.4≥ 3.0.0.0, ≤ 3.0.0.12v2.1.1.22018-03-09
CVE-2016-0253 [MEDIUM] CWE-79 CVE-2016-0253: Cross-site scripting (XSS) vulnerability in IBM Financial Transaction Manager (FTM) for ACH Services
Cross-site scripting (XSS) vulnerability in IBM Financial Transaction Manager (FTM) for ACH Services for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013, Financial Transaction Manager (FTM) for Check Services for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013, and Financial Transaction Manager (FTM) for Corporate Payment Services (CPS) for Multi-Pla
nvd
CVE-2016-0274P4MEDIUMCVSS 5.4≥ 3.0.0.0, ≤ 3.0.0.12v2.1.1.22018-03-09
CVE-2016-0274 [MEDIUM] CWE-254 CVE-2016-0274: IBM Financial Transaction Manager (FTM) for ACH Services for Multi-Platform 2.1.1.2 and 3.0.0.x befo
IBM Financial Transaction Manager (FTM) for ACH Services for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013, Financial Transaction Manager (FTM) for Check Services for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013, and Financial Transaction Manager (FTM) for Corporate Payment Services (CPS) for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013 all
nvd
CVE-2020-4560P4MEDIUMCVSS 6.1v3.2.4.0v3.2.42020-08-03
CVE-2020-4560 [MEDIUM] CWE-79 CVE-2020-4560: IBM Financial Transaction Manager 3.2.4 is vulnerable to cross-site scripting. This vulnerability al
IBM Financial Transaction Manager 3.2.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
nvd
CVE-2019-4744P4MEDIUMCVSS 6.1v3.02019-12-20
CVE-2019-4744 [MEDIUM] CWE-79 CVE-2019-4744: IBM Financial Transaction Manager 3.0 is vulnerable to cross-site scripting. This vulnerability allo
IBM Financial Transaction Manager 3.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 172882.
nvd
CVE-2018-1871P4MEDIUMCVSS 5.4v3.0.0.0v3.0.2.0+5 more2018-12-06
CVE-2018-1871 [MEDIUM] CWE-79 CVE-2018-1871: IBM Financial Transaction Manager for Digital Payments for Multi-Platform 3.0.0, 3.0.2, and 3.0.5 is
IBM Financial Transaction Manager for Digital Payments for Multi-Platform 3.0.0, 3.0.2, and 3.0.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 151329.
nvd
CVE-2018-1390P4MEDIUMCVSS 5.4v3.0.0.0v3.0.2.0+4 more2018-03-30
CVE-2018-1390 [MEDIUM] CWE-79 CVE-2018-1390: IBM Financial Transaction Manager for Check Services for Multi-Platform 3.0, 3.0.2, and 3.0.2.1 is v
IBM Financial Transaction Manager for Check Services for Multi-Platform 3.0, 3.0.2, and 3.0.2.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 138221.
nvd
CVE-2020-4908P4MEDIUMCVSS 5.3v3.2.42020-12-16
CVE-2020-4908 [MEDIUM] CWE-200 CVE-2020-4908: IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4 returns the product ve
IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4 returns the product version and release information on the login dialog. This information could be used in further attacks against the system.
nvd
CVE-2020-4907P4MEDIUMCVSS 5.3v3.2.42020-12-16
CVE-2020-4907 [MEDIUM] CWE-209 CVE-2020-4907: IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4 could allow a remote a
IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.
nvd
CVE-2017-1160P4MEDIUMCVSS 5.4v3.0.0.0v3.0.0.1+14 more2017-04-17
CVE-2017-1160 [MEDIUM] CWE-79 CVE-2017-1160: IBM Financial Transaction Manager for ACH Services for Multi-Platform 3.0.0.x is vulnerable to cross
IBM Financial Transaction Manager for ACH Services for Multi-Platform 3.0.0.x is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 122892.
nvd
CVE-2021-29841P4MEDIUMCVSS 5.4v3.2.42021-09-14
CVE-2021-29841 [MEDIUM] CWE-79 CVE-2021-29841: IBM Financial Transaction Manager 3.2.4 is vulnerable to cross-site scripting. This vulnerability al
IBM Financial Transaction Manager 3.2.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 205045.
nvd
CVE-2020-5000P4MEDIUMCVSS 5.4v3.0.2v3.2.4+1 more2021-06-15
CVE-2020-5000 [MEDIUM] CWE-79 CVE-2020-5000: IBM Financial Transaction Manager 3.2.0 through 3.2.8 is vulnerable to cross-site scripting. This vu
IBM Financial Transaction Manager 3.2.0 through 3.2.8 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 192952.
nvd
CVE-2016-5920P4MEDIUMCVSS 5.4v3.0.0.0v3.0.0.1+14 more2016-10-29
CVE-2016-5920 [MEDIUM] CWE-79 CVE-2016-5920: Cross-site scripting (XSS) vulnerability in the Web UI in IBM Financial Transaction Manager (FTM) fo
Cross-site scripting (XSS) vulnerability in the Web UI in IBM Financial Transaction Manager (FTM) for ACH Services 3.0.0.x before fp0015 and 3.0.1.0 before iFix0002 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
nvd