IBM Financial Transaction Manager 3.2.0.0 for Digital Payments

CPE Details

IBM Financial Transaction Manager 3.2.0.0 for Digital Payments
3.2.0.0
2018-11-20
12h27 +00:00
2018-11-20
12h27 +00:00
Alerte pour un CPE
Restez informé de toutes modifications pour un CPE spécifique.
Gestion des notifications

CPE Name: cpe:2.3:a:ibm:financial_transaction_manager:3.2.0.0:*:*:*:*:digital_payments:*:*

Informations

Vendor

ibm

Product

financial_transaction_manager

Version

3.2.0.0

Target Software

digital_payments

Related CVE

Open and find in CVE List

CVE ID Publié Description Score Gravité
CVE-2020-5026 2023-03-01 21h28 +00:00 IBM Financial Transaction Manager for Digital Payments for Multi-Platform 3.2.0 through 3.2.7 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 193662.
7.5
Haute
CVE-2020-5002 2023-03-01 21h16 +00:00 IBM Financial Transaction Manager 3.2.0 through 3.2.10 could allow an authenticated user to perform unauthorized actions due to improper validation. IBM X-Force ID: 192954.
8.8
Haute
CVE-2020-5001 2023-03-01 21h10 +00:00 IBM Financial Transaction Manager 3.2.0 through 3.2.7 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 192953.
7.5
Haute
CVE-2019-4575 2022-06-15 15h40 +00:00 IBM Financial Transaction Manager for Digital Payments for Multi-Platform 3.2.0 through 3.2.9 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 166801.
9.8
Critique
CVE-2018-1819 2018-10-04 15h00 +00:00 IBM Financial Transaction Manager for Digital Payments for Multi-Platform 3.0.2, 3.0.4, 3.0.6, and 3.2.0 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-force ID: 150023.
8.8
Haute