First published: Mon Dec 11 2017(Updated: )
IBM Financial Transaction Manager (FTM) for Multi-Platform (MP) 3.0.0.0 through 3.0.0.7 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 132926.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ibm Financial Transaction Manager | =3.0.0.0 | |
Ibm Financial Transaction Manager | =3.0.0.1 | |
Ibm Financial Transaction Manager | =3.0.0.2 | |
Ibm Financial Transaction Manager | =3.0.0.3 | |
Ibm Financial Transaction Manager | =3.0.0.4 | |
Ibm Financial Transaction Manager | =3.0.0.5 | |
Ibm Financial Transaction Manager | =3.0.0.6 | |
Ibm Financial Transaction Manager | =3.0.0.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2017-1606 is high.
CVE-2017-1606 affects IBM Financial Transaction Manager versions 3.0.0.0 through 3.0.0.7 on Multi-Platform (MP).
CVE-2017-1606 is a SQL injection vulnerability.
An attacker can exploit CVE-2017-1606 by sending specially-crafted SQL statements, allowing them to view, add, modify, or delete information in the back-end database.
Yes, you can find references for CVE-2017-1606 at the following links: [link1], [link2], [link3].