CVE-2016-0276: Input Validation
IBM Financial Transaction Manager (FTM) for ACH Services for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013, Financial Transaction Manager (FTM) for Check Services for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013, and Financial Transaction Manager (FTM) for Corporate Payment Services (CPS) for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013 allows remote attackers to execute arbitrary code via a crafted serialized Java Message Service (JMS) ObjectMessage object. IBM X-Force ID: 111084.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-0276?
The severity of CVE-2016-0276 is medium with a score of 6.3.
Which software versions of IBM Financial Transaction Manager (FTM) for ACH Services for Multi-Platform are affected by CVE-2016-0276?
The software versions affected by CVE-2016-0276 are 2.1.1.2 and 3.0.0.x before fp0013.
Which software versions of IBM Financial Transaction Manager (FTM) for Check Services for Multi-Platform are affected by CVE-2016-0276?
The software versions affected by CVE-2016-0276 are 2.1.1.2 and 3.0.0.x before fp0013.
Which software versions of IBM Financial Transaction Manager (FTM) for Corporate Payment Services (CPS) are affected by CVE-2016-0276?
The software versions affected by CVE-2016-0276 are 2.1.1.2 and 3.0.0.x before fp0013.
How can I fix CVE-2016-0276?
To fix CVE-2016-0276, upgrade to Financial Transaction Manager (FTM) for ACH Services, Check Services, and Corporate Payment Services version 3.0.0.x fp0013 or later.