CVE-2020-4555
https://notcve.org/view.php?id=CVE-2020-4555
IBM Financial Transaction Manager 3.0.6 and 3.1.0 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 183328. IBM Financial Transaction Manager versiones 3.0.6 y 3.1.0, no comprueba una sesión después del cierre de sesión, lo que podría permitir a un usuario autenticado suplantar a otro usuario en el sistema. IBM X-Force ID: 183328 • https://exchange.xforce.ibmcloud.com/vulnerabilities/183328 https://www.ibm.com/support/pages/node/6388702 https://www.ibm.com/support/pages/node/6388704 https://www.ibm.com/support/pages/node/6388706 https://www.ibm.com/support/pages/node/6388708 https://www.ibm.com/support/pages/node/6388722 https://www.ibm.com/support/pages/node/6388744 • CWE-384: Session Fixation •
CVE-2016-0275
https://notcve.org/view.php?id=CVE-2016-0275
IBM Financial Transaction Manager (FTM) for ACH Services for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013, Financial Transaction Manager (FTM) for Check Services for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013, and Financial Transaction Manager (FTM) for Corporate Payment Services (CPS) for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013 allows local users to obtain sensitive information via vectors related to cacheable HTTPS responses. IBM Financial Transaction Manager (FTM) for ACH Services for Multi-Platform 2.1.1.2 y versiones 3.0.0.x anteriores a fp0013; Financial Transaction Manager (FTM) for Check Services for Multi-Platform 2.1.1.2 y versiones 3.0.0.x anteriores a fp0013 y Financial Transaction Manager (FTM) for Corporate Payment Services (CPS) for Multi-Platform 2.1.1.2 y versiones 3.0.0.x anteriores a fp0013 permiten que usuarios locales obtengan información sensible mediante vectores relacionados con respuestas HTTPS cacheables. • http://www-01.ibm.com/support/docview.wss?uid=swg21977245 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2016-0274
https://notcve.org/view.php?id=CVE-2016-0274
IBM Financial Transaction Manager (FTM) for ACH Services for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013, Financial Transaction Manager (FTM) for Check Services for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013, and Financial Transaction Manager (FTM) for Corporate Payment Services (CPS) for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013 allows remote attackers to conduct clickjacking attacks via a crafted web site. IBM X-Force ID: 111076. IBM Financial Transaction Manager (FTM) for ACH Services for Multi-Platform 2.1.1.2 y versiones 3.0.0.x anteriores a fp0013; Financial Transaction Manager (FTM) for Check Services for Multi-Platform 2.1.1.2 y versiones 3.0.0.x anteriores a fp0013 y Financial Transaction Manager (FTM) for Corporate Payment Services (CPS) for Multi-Platform 2.1.1.2 y versiones 3.0.0.x anteriores a fp0013 permiten que atacantes remotos lleven a cabo ataques de secuestro de clic (clickjacking) mediante un sitio web manipulado. IBM X-Force ID: 111076. • http://www-01.ibm.com/support/docview.wss?uid=swg21977245 https://exchange.xforce.ibmcloud.com/vulnerabilities/111076 • CWE-254: 7PK - Security Features •
CVE-2016-0272
https://notcve.org/view.php?id=CVE-2016-0272
Cross-site request forgery (CSRF) vulnerability in IBM Financial Transaction Manager (FTM) for ACH Services for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013, Financial Transaction Manager (FTM) for Check Services for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013, and Financial Transaction Manager (FTM) for Corporate Payment Services (CPS) for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013 allows remote attackers to hijack the authentication of arbitrary users via unspecified vectors. IBM X-Force ID: 111052. Vulnerabilidad de Cross-Site Request Forgery (CSRF) en IBM Financial Transaction Manager (FTM) for ACH Services for Multi-Platform 2.1.1.2 y versiones 3.0.0.x anteriores a fp0013; Financial Transaction Manager (FTM) for Check Services for Multi-Platform 2.1.1.2 y versiones 3.0.0.x anteriores a fp0013 y Financial Transaction Manager (FTM) for Corporate Payment Services (CPS) for Multi-Platform 2.1.1.2 y versiones 3.0.0.x anteriores a fp0013 permite que atacantes remotos secuestren la autenticación de usuarios arbitrarios mediante vectores sin especificar. IBM X-Force ID: 111052. • http://www-01.ibm.com/support/docview.wss?uid=swg21977245 https://exchange.xforce.ibmcloud.com/vulnerabilities/111052 • CWE-352: Cross-Site Request Forgery (CSRF) •
CVE-2016-0253
https://notcve.org/view.php?id=CVE-2016-0253
Cross-site scripting (XSS) vulnerability in IBM Financial Transaction Manager (FTM) for ACH Services for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013, Financial Transaction Manager (FTM) for Check Services for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013, and Financial Transaction Manager (FTM) for Corporate Payment Services (CPS) for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 110562. Vulnerabilidad de Cross-Site Scripting (XSS) en IBM Financial Transaction Manager (FTM) for ACH Services for Multi-Platform 2.1.1.2 y versiones 3.0.0.x anteriores a fp0013; Financial Transaction Manager (FTM) for Check Services for Multi-Platform 2.1.1.2 y versiones 3.0.0.x anteriores a fp0013 y Financial Transaction Manager (FTM) for Corporate Payment Services (CPS) for Multi-Platform 2.1.1.2 y versiones 3.0.0.x anteriores a fp0013 permite que atacantes remotos inyecten scripts web o HTML arbitrarios mediante vectores sin especificar. IBM X-Force ID: 110562. • http://www-01.ibm.com/support/docview.wss?uid=swg21977245 https://exchange.xforce.ibmcloud.com/vulnerabilities/110562 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •