First published: Fri Mar 09 2018(Updated: )
Cross-site request forgery (CSRF) vulnerability in IBM Financial Transaction Manager (FTM) for ACH Services for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013, Financial Transaction Manager (FTM) for Check Services for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013, and Financial Transaction Manager (FTM) for Corporate Payment Services (CPS) for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013 allows remote attackers to hijack the authentication of arbitrary users via unspecified vectors. IBM X-Force ID: 111052.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ibm Financial Transaction Manager | >=3.0.0.0<=3.0.0.12 | |
Ibm Financial Transaction Manager | >=3.0.0.0<=3.0.0.12 | |
Ibm Financial Transaction Manager | >=3.0.0.0<=3.0.0.12 | |
Ibm Financial Transaction Manager | =2.1.1.2 | |
Ibm Financial Transaction Manager | =2.1.1.2 | |
Ibm Financial Transaction Manager | =2.1.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2016-0272 is high with a severity value of 8.
The affected software for CVE-2016-0272 is IBM Financial Transaction Manager (FTM) for ACH Services for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013, Financial Transaction Manager (FTM) for Check Services for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013, and Financial Transaction Manager (FTM) for CPS Services for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013.
The CWE of CVE-2016-0272 is 352.
To fix the CSRF vulnerability in IBM Financial Transaction Manager (FTM) for ACH Services for Multi-Platform, you should update to version 3.0.0.x fp0013 or later.
You can find more information about CVE-2016-0272 on the IBM Support website and the IBM X-Force Exchange website.