First published: Sat Oct 29 2016(Updated: )
Cross-site scripting (XSS) vulnerability in the Web UI in IBM Financial Transaction Manager (FTM) for ACH Services 3.0.0.x before fp0015 and 3.0.1.0 before iFix0002 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ibm Financial Transaction Manager | =3.0.0.0 | |
Ibm Financial Transaction Manager | =3.0.0.1 | |
Ibm Financial Transaction Manager | =3.0.0.2 | |
Ibm Financial Transaction Manager | =3.0.0.3 | |
Ibm Financial Transaction Manager | =3.0.0.4 | |
Ibm Financial Transaction Manager | =3.0.0.5 | |
Ibm Financial Transaction Manager | =3.0.0.6 | |
Ibm Financial Transaction Manager | =3.0.0.7 | |
Ibm Financial Transaction Manager | =3.0.0.8 | |
Ibm Financial Transaction Manager | =3.0.0.9 | |
Ibm Financial Transaction Manager | =3.0.0.10 | |
Ibm Financial Transaction Manager | =3.0.0.11 | |
Ibm Financial Transaction Manager | =3.0.0.12 | |
Ibm Financial Transaction Manager | =3.0.0.13 | |
Ibm Financial Transaction Manager | =3.0.0.14 | |
Ibm Financial Transaction Manager | =3.0.0.0 | |
Ibm Financial Transaction Manager | =3.0.0.1 | |
Ibm Financial Transaction Manager | =3.0.0.2 | |
Ibm Financial Transaction Manager | =3.0.0.3 | |
Ibm Financial Transaction Manager | =3.0.0.4 | |
Ibm Financial Transaction Manager | =3.0.0.5 | |
Ibm Financial Transaction Manager | =3.0.0.6 | |
Ibm Financial Transaction Manager | =3.0.0.7 | |
Ibm Financial Transaction Manager | =3.0.0.8 | |
Ibm Financial Transaction Manager | =3.0.0.9 | |
Ibm Financial Transaction Manager | =3.0.0.10 | |
Ibm Financial Transaction Manager | =3.0.0.11 | |
Ibm Financial Transaction Manager | =3.0.0.12 | |
Ibm Financial Transaction Manager | =3.0.0.13 | |
Ibm Financial Transaction Manager | =3.0.0.14 | |
Ibm Financial Transaction Manager | =3.0.1.0 | |
Ibm Financial Transaction Manager | =3.0.0.0 | |
Ibm Financial Transaction Manager | =3.0.0.1 | |
Ibm Financial Transaction Manager | =3.0.0.2 | |
Ibm Financial Transaction Manager | =3.0.0.3 | |
Ibm Financial Transaction Manager | =3.0.0.4 | |
Ibm Financial Transaction Manager | =3.0.0.5 | |
Ibm Financial Transaction Manager | =3.0.0.6 | |
Ibm Financial Transaction Manager | =3.0.0.7 | |
Ibm Financial Transaction Manager | =3.0.0.8 | |
Ibm Financial Transaction Manager | =3.0.0.9 | |
Ibm Financial Transaction Manager | =3.0.0.10 | |
Ibm Financial Transaction Manager | =3.0.0.11 | |
Ibm Financial Transaction Manager | =3.0.0.12 | |
Ibm Financial Transaction Manager | =3.0.0.13 | |
Ibm Financial Transaction Manager | =3.0.0.14 | |
Ibm Financial Transaction Manager | =3.0.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-5920 has a medium severity rating due to its potential for cross-site scripting attacks.
To fix CVE-2016-5920, upgrade IBM Financial Transaction Manager to version 3.0.0.x after fp0015 or 3.0.1.0 after iFix0002.
CVE-2016-5920 affects users of IBM Financial Transaction Manager for ACH Services versions prior to the specified fixes.
CVE-2016-5920 is a cross-site scripting (XSS) vulnerability which allows remote authenticated users to inject malicious scripts.
No, CVE-2016-5920 requires an authenticated user to exploit the vulnerability.