CVE-2018-1390: XSS
IBM Financial Transaction Manager for Check Services for Multi-Platform 3.0, 3.0.2, and 3.0.2.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 138221.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID of IBM Financial Transaction Manager for Check Services for Multi-Platform?
The vulnerability ID is CVE-2018-1390.
What is the severity level of CVE-2018-1390?
The severity level of CVE-2018-1390 is medium with a severity value of 5.4.
How does CVE-2018-1390 impact IBM Financial Transaction Manager for Check Services for Multi-Platform?
CVE-2018-1390 allows users to embed arbitrary JavaScript code in the Web UI, potentially leading to credentials disclosure.
Which versions of IBM Financial Transaction Manager for Check Services for Multi-Platform are affected by CVE-2018-1390?
Versions 3.0, 3.0.2, and 3.0.2.1 of IBM Financial Transaction Manager for Check Services for Multi-Platform are affected by CVE-2018-1390.
How can I fix the cross-site scripting vulnerability in IBM Financial Transaction Manager for Check Services for Multi-Platform?
To fix the vulnerability, apply the necessary security patches or updates provided by IBM.