
CVE-2017-1152
https://notcve.org/view.php?id=CVE-2017-1152
14 Apr 2017 — IBM Financial Transaction Manager 3.0.1 and 3.0.2 does not properly update the SESSIONID with each request, which could allow a user to obtain the ID in further attacks against the system. IBM X-Force ID: 122293. IBM Financial Transaction Manager 3.0.1 y 3.0.2 no actualiza correctamente el SESSIONID con cada solicitud, lo que podría permitir a un usuario obtener el ID en nuevos ataques contra el sistema. IBM X-Force ID: 122293. • http://www.ibm.com/support/docview.wss?uid=swg22001551 • CWE-384: Session Fixation •

CVE-2016-3060
https://notcve.org/view.php?id=CVE-2016-3060
29 Oct 2016 — Payments Director in IBM Financial Transaction Manager (FTM) for ACH Services, Check Services, and Corporate Payment Services (CPS) 3.0.0.x before fp0015 and 3.0.1.0 before iFix0002 allows remote authenticated users to conduct clickjacking attacks via a crafted web site. Payments Director en IBM Financial Transaction Manager (FTM) para ACH Services, Check Services y Corporate Payment Services (CPS) 3.0.0.x en versiones anteriores a fp0015 y 3.0.1.0 en versiones anteriores a iFix0002 permite a usuarios remot... • http://www-01.ibm.com/support/docview.wss?uid=swg1PI64063 • CWE-284: Improper Access Control •

CVE-2016-5920
https://notcve.org/view.php?id=CVE-2016-5920
29 Oct 2016 — Cross-site scripting (XSS) vulnerability in the Web UI in IBM Financial Transaction Manager (FTM) for ACH Services 3.0.0.x before fp0015 and 3.0.1.0 before iFix0002 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. Vulnerabilidad de XSS en la Web UI en IBM Financial Transaction Manager (FTM) para ACH Services 3.0.0.x en versiones anteriores a fp0015 y 3.0.1.0 en versiones anteriores a iFix0002 permite a usuarios remotos autenticados inyectar secuencias de coma... • http://www-01.ibm.com/support/docview.wss?uid=swg1PI67537 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2016-0231
https://notcve.org/view.php?id=CVE-2016-0231
15 Feb 2016 — IBM Financial Transaction Manager (FTM) for ACH Services, Check Services and Corporate Payment Services (CPS) 3.0.0 before FP12 allows remote authenticated users to obtain sensitive information by reading exception details in error logs. IBM Financial Transaction Manager (FTM) para ACH Services, Check Services y Corporate Payment Services (CPS) 3.0.0 en versiones anteriores a FP12 permite a usuarios remotos autenticados obtener información sensible mediante la lectura de detalles de excepción en logs de err... • http://www-01.ibm.com/support/docview.wss?uid=swg1PI56757 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2016-0232
https://notcve.org/view.php?id=CVE-2016-0232
15 Feb 2016 — IBM Financial Transaction Manager (FTM) for ACH Services, Check Services and Corporate Payment Services (CPS) 3.0.0 before FP12 allows remote authenticated users to obtain sensitive information by reading README files. IBM Financial Transaction Manager (FTM) para ACH Services, Check Services y Corporate Payment Services (CPS) 3.0.0 en versiones anteriores a FP12 permite a usuarios remotos autenticados obtener información sensible mediante la lectura de archivos README. • http://www-01.ibm.com/support/docview.wss?uid=swg1PI56757 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2014-8917
https://notcve.org/view.php?id=CVE-2014-8917
28 Jan 2015 — Multiple cross-site scripting (XSS) vulnerabilities in (1) dojox/form/resources/uploader.swf (aka upload.swf), (2) dojox/form/resources/fileuploader.swf (aka fileupload.swf), (3) dojox/av/resources/audio.swf, and (4) dojox/av/resources/video.swf in the IBM Dojo Toolkit, as used in IBM Social Media Analytics 1.3 before IF11 and other products, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. Múltiples vulnerabilidades de XSS en (1) dojox/form/resources/uploader.swf (tamb... • http://secunia.com/advisories/62590 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2014-0830
https://notcve.org/view.php?id=CVE-2014-0830
01 Feb 2014 — Directory traversal vulnerability in the table-export implementation in the OAC component in IBM Financial Transaction Manager (FTM) 2.0 before 2.0.0.3 and 2.1 before 2.1.0.1 allows remote authenticated users to read arbitrary files via a modified pathname. Vulnerabilidad de salto de directorio en la implementación de table-export en el componente OAC de IBM Financial Transaction Manager (FTM) 2.0 anterior a 2.0.0.3 y 2.1 anterior a 2.1.0.1 permite a usuarios remotos autenticados leer archivos arbitrarios a... • http://www-01.ibm.com/support/docview.wss?uid=swg21662714 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •

CVE-2014-0831
https://notcve.org/view.php?id=CVE-2014-0831
01 Feb 2014 — Cross-site request forgery (CSRF) vulnerability in the OAC component in IBM Financial Transaction Manager (FTM) 2.0 before 2.0.0.3 allows remote attackers to hijack the authentication of arbitrary users for requests that modify configuration data. Vulnerabilidad de CSRF en el componente OAC de IBM Financial Transaction Manager (FTM) 2.0 anterior a 2.0.0.3 permite a atacantes remotos secuestrar la autenticación de usuarios arbitrarios para peticiones que modifican datos de configuración. • http://osvdb.org/102766 • CWE-352: Cross-Site Request Forgery (CSRF) •

CVE-2014-0832
https://notcve.org/view.php?id=CVE-2014-0832
01 Feb 2014 — Multiple cross-site scripting (XSS) vulnerabilities in configuration-details screens in the OAC component in IBM Financial Transaction Manager (FTM) 2.0 before 2.0.0.3 allow remote authenticated users to inject arbitrary web script or HTML via a crafted text value. Múltiples vulnerabilidades XSS en las pantallas de detalle de configuración del componente OAC de IBM Financial Transaction Manager (FTM) 2.0 anterior a 2.0.0.3 permite a usuarios remotos autenticados inyectar script Web o HTML arbitrario a travé... • http://www-01.ibm.com/support/docview.wss?uid=swg21662714 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2014-0833
https://notcve.org/view.php?id=CVE-2014-0833
01 Feb 2014 — The OAC component in IBM Financial Transaction Manager (FTM) 2.0 before 2.0.0.3 does not properly enforce operator-intervention requirements, which allows remote authenticated users to bypass intended access restrictions via an unspecified process step. El componente OAC de IBM Financial Transaction Manager (FTM) 2.0 anterior a 2.0.0.3 no fuerza apropiadamente los requisitos de la intervención del operador, lo cual permite a usuarios remotos autenticados evadir restricciones de acceso a través de una etapa ... • http://osvdb.org/102767 • CWE-264: Permissions, Privileges, and Access Controls •