VendorsIBMtransformation_extender_advancedall versions
Vulnerabilities

IBM Transformation Extender Advanced

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7CVEs
CVE-2023-49886
IBM Transformation Extender Advanced code execution
Published 2025-10-06 · Analyzed
9.8EPSS 0.007
CVE-2023-49881
IBM Transformation Extender Advanced session fixation
Published 2025-10-01 · Analyzed
8.8EPSS 0.002
CVE-2023-49883
IBM Transformation Extender Advanced information disclosure
Published 2025-10-01 · Analyzed
7.5EPSS 0.003
CVE-2017-1758
IBM Financial Transaction Manager for ACH Services for Multi-Platform (IBM Control Center 6.0 and 6.1, IBM Financial Transaction Manager 3.0.2, 3.0.3, 3.0.4, and 3.1.0, IBM Transformation Extender Advanced 9.0) is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 135859.
Published 2018-02-21 · Modified
7.1EPSS 0.016
CVE-2023-50300
IBM Transformation Extender Advanced improper access control
Published 2025-10-01 · Analyzed
6.2EPSS 0.001
CVE-2023-50301
IBM Transformation Extender Advanced information disclosure
Published 2025-10-01 · Analyzed
4.4EPSS 0.001
CVE-2021-29883
IBM Standards Processing Engine (IBM Transformation Extender Advanced 9.0 and 10.0) does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. IBM X-Force ID: 207090.
Published 2021-10-21 · Modified
4.3EPSS 0.005