VendorsIBMfinancial_transaction_managerall versions
Vulnerabilities

IBM Financial Transaction Manager

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

46CVEs
CVE-2017-1152
IBM Financial Transaction Manager 3.0.1 and 3.0.2 does not properly update the SESSIONID with each request, which could allow a user to obtain the ID in further attacks against the system. IBM X-Force ID: 122293.
Published 2017-04-14 · Modified
4.3EPSS 0.006
CVE-2014-0830
Directory traversal vulnerability in the table-export implementation in the OAC component in IBM Financial Transaction Manager (FTM) 2.0 before 2.0.0.3 and 2.1 before 2.1.0.1 allows remote authenticated users to read arbitrary files via a modified pathname.
Published 2014-02-01 · Modified
4.0EPSS 0.014
CVE-2020-4556
IBM Financial Transaction Manager information disclosure
Published 2023-03-15 · Modified
4.0EPSS 0.002
CVE-2014-0832
Multiple cross-site scripting (XSS) vulnerabilities in configuration-details screens in the OAC component in IBM Financial Transaction Manager (FTM) 2.0 before 2.0.0.3 allow remote authenticated users to inject arbitrary web script or HTML via a crafted text value.
Published 2014-02-01 · Modified
3.5EPSS 0.008
CVE-2018-1392
IBM Financial Transaction Manager 3.0.4 and 3.1.0 for ACH Services for Multi-Platform could allow an authenticated user to execute a specially crafted command that could obtain sensitive information. IBM X-Force ID: 138377.
Published 2018-02-22 · Modified
3.5EPSS 0.006
CVE-2016-0275
IBM Financial Transaction Manager (FTM) for ACH Services for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013, Financial Transaction Manager (FTM) for Check Services for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013, and Financial Transaction Manager (FTM) for Corporate Payment Services (CPS) for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013 allows local users to obtain sensitive information via vectors related to cacheable HTTPS responses.
Published 2018-03-09 · Modified
3.3EPSS 0.003
← Prev2 / 2