First published: Fri Jul 31 2020(Updated: )
IBM Financial Transaction Manager 3.2.4 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 177839.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ibm Financial Transaction Manager For Multiplatform | =3.2.4 | |
<=3.2.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-4328.
The severity of CVE-2020-4328 is medium with a CVSS score of 6.3.
IBM Financial Transaction Manager version 3.2.4 is affected by CVE-2020-4328.
You can fix CVE-2020-4328 by applying the patch provided by IBM. Please visit the IBM support page for the patch download link.
The Common Weakness Enumeration (CWE) for CVE-2020-4328 is CWE-89 (SQL Injection).