CVE-2020-4328: SQL Injection
IBM Financial Transaction Manager 3.2.4 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 177839.
Other sources
IBM Financial Transaction Manager is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2020-4328.
What is the severity of CVE-2020-4328?
The severity of CVE-2020-4328 is medium with a CVSS score of 6.3.
Which software versions are affected by CVE-2020-4328?
IBM Financial Transaction Manager version 3.2.4 is affected by CVE-2020-4328.
How can I fix CVE-2020-4328?
You can fix CVE-2020-4328 by applying the patch provided by IBM. Please visit the IBM support page for the patch download link.
What is the Common Weakness Enumeration (CWE) for CVE-2020-4328?
The Common Weakness Enumeration (CWE) for CVE-2020-4328 is CWE-89 (SQL Injection).