First published: Fri Mar 30 2018(Updated: )
IBM Financial Transaction Manager for Check Services for Multi-Platform 3.0, 3.0.2, and 3.0.2.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 138221.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ibm Financial Transaction Manager | =3.0.0.0 | |
Ibm Financial Transaction Manager | =3.0.2.0 | |
Ibm Financial Transaction Manager | =3.0.2.1 | |
Ibm Financial Transaction Manager | =3.0.5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2018-1390.
The severity level of CVE-2018-1390 is medium with a severity value of 5.4.
CVE-2018-1390 allows users to embed arbitrary JavaScript code in the Web UI, potentially leading to credentials disclosure.
Versions 3.0, 3.0.2, and 3.0.2.1 of IBM Financial Transaction Manager for Check Services for Multi-Platform are affected by CVE-2018-1390.
To fix the vulnerability, apply the necessary security patches or updates provided by IBM.