
CVE-2020-4555
https://notcve.org/view.php?id=CVE-2020-4555
21 Dec 2020 — IBM Financial Transaction Manager 3.0.6 and 3.1.0 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 183328. IBM Financial Transaction Manager versiones 3.0.6 y 3.1.0, no comprueba una sesión después del cierre de sesión, lo que podría permitir a un usuario autenticado suplantar a otro usuario en el sistema. IBM X-Force ID: 183328 • https://exchange.xforce.ibmcloud.com/vulnerabilities/183328 • CWE-384: Session Fixation •

CVE-2016-0253
https://notcve.org/view.php?id=CVE-2016-0253
09 Mar 2018 — Cross-site scripting (XSS) vulnerability in IBM Financial Transaction Manager (FTM) for ACH Services for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013, Financial Transaction Manager (FTM) for Check Services for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013, and Financial Transaction Manager (FTM) for Corporate Payment Services (CPS) for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 110562. Vulner... • http://www-01.ibm.com/support/docview.wss?uid=swg21977245 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2016-0268
https://notcve.org/view.php?id=CVE-2016-0268
09 Mar 2018 — XML external entity (XXE) vulnerability in IBM Financial Transaction Manager (FTM) for ACH Services for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013, Financial Transaction Manager (FTM) for Check Services for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013, and Financial Transaction Manager (FTM) for Corporate Payment Services (CPS) for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013 allows remote authenticated users to obtain sensitive information via crafted XML data. IBM X-Force ID: 110915. Vulnera... • http://www-01.ibm.com/support/docview.wss?uid=swg21977245 • CWE-611: Improper Restriction of XML External Entity Reference •

CVE-2016-0272
https://notcve.org/view.php?id=CVE-2016-0272
09 Mar 2018 — Cross-site request forgery (CSRF) vulnerability in IBM Financial Transaction Manager (FTM) for ACH Services for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013, Financial Transaction Manager (FTM) for Check Services for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013, and Financial Transaction Manager (FTM) for Corporate Payment Services (CPS) for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013 allows remote attackers to hijack the authentication of arbitrary users via unspecified vectors. IBM X-Force ID... • http://www-01.ibm.com/support/docview.wss?uid=swg21977245 • CWE-352: Cross-Site Request Forgery (CSRF) •

CVE-2016-0274
https://notcve.org/view.php?id=CVE-2016-0274
09 Mar 2018 — IBM Financial Transaction Manager (FTM) for ACH Services for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013, Financial Transaction Manager (FTM) for Check Services for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013, and Financial Transaction Manager (FTM) for Corporate Payment Services (CPS) for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013 allows remote attackers to conduct clickjacking attacks via a crafted web site. IBM X-Force ID: 111076. IBM Financial Transaction Manager (FTM) for ACH Services f... • http://www-01.ibm.com/support/docview.wss?uid=swg21977245 • CWE-254: 7PK - Security Features •

CVE-2016-0275
https://notcve.org/view.php?id=CVE-2016-0275
09 Mar 2018 — IBM Financial Transaction Manager (FTM) for ACH Services for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013, Financial Transaction Manager (FTM) for Check Services for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013, and Financial Transaction Manager (FTM) for Corporate Payment Services (CPS) for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013 allows local users to obtain sensitive information via vectors related to cacheable HTTPS responses. IBM Financial Transaction Manager (FTM) for ACH Services for ... • http://www-01.ibm.com/support/docview.wss?uid=swg21977245 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2014-8917
https://notcve.org/view.php?id=CVE-2014-8917
28 Jan 2015 — Multiple cross-site scripting (XSS) vulnerabilities in (1) dojox/form/resources/uploader.swf (aka upload.swf), (2) dojox/form/resources/fileuploader.swf (aka fileupload.swf), (3) dojox/av/resources/audio.swf, and (4) dojox/av/resources/video.swf in the IBM Dojo Toolkit, as used in IBM Social Media Analytics 1.3 before IF11 and other products, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. Múltiples vulnerabilidades de XSS en (1) dojox/form/resources/uploader.swf (tamb... • http://secunia.com/advisories/62590 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •