First published: Fri Mar 09 2018(Updated: )
XML external entity (XXE) vulnerability in IBM Financial Transaction Manager (FTM) for ACH Services for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013, Financial Transaction Manager (FTM) for Check Services for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013, and Financial Transaction Manager (FTM) for Corporate Payment Services (CPS) for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013 allows remote authenticated users to obtain sensitive information via crafted XML data. IBM X-Force ID: 110915.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ibm Financial Transaction Manager | >=3.0.0.0<=3.0.0.12 | |
Ibm Financial Transaction Manager | >=3.0.0.0<=3.0.0.12 | |
Ibm Financial Transaction Manager | >=3.0.0.0<=3.0.0.12 | |
Ibm Financial Transaction Manager | =2.1.1.2 | |
Ibm Financial Transaction Manager | =2.1.1.2 | |
Ibm Financial Transaction Manager | =2.1.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2016-0268.
The severity of CVE-2016-0268 is medium.
IBM Financial Transaction Manager (FTM) for ACH Services, Financial Transaction Manager (FTM) for Check Services, and Financial Transaction Manager (FTM) for CPS Services are affected by CVE-2016-0268.
The affected versions of the software range from 2.1.1.2 to 3.0.0.12.
Apply fp0013 for Multi-Platform 2.1.1.2 and 3.0.0.x versions of IBM Financial Transaction Manager (FTM) for ACH Services, Financial Transaction Manager (FTM) for Check Services, and Financial Transaction Manager (FTM) for CPS Services.