First published: Wed Dec 11 2019(Updated: )
IBM Financial Transaction Manager 3.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. IBM X-Force ID: 172880.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ibm Financial Transaction Manager For Multiplatform | =3.0.0.0 | |
IBM Financial Transaction Manager for SWIFT Services for Multiplatforms | <=3.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2019-4743.
The title of this vulnerability is 'IBM Financial Transaction Manager 3.0 does not set the secure attribute on authorization tokens or session cookies.'
The severity rating of CVE-2019-4743 is medium with a value of 4.3.
The affected software is IBM Financial Transaction Manager 3.0.
Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to.
Yes, you can find references for this vulnerability at the following links: https://exchange.xforce.ibmcloud.com/vulnerabilities/172880 and https://www.ibm.com/support/pages/node/1135173.
The Common Weakness Enumeration (CWE) ID for this vulnerability is 319.