First published: Fri Dec 18 2020(Updated: )
IBM Financial Transaction Manager 3.0.6 and 3.1.0 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 183328.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ibm Financial Transaction Manager | =2.1.1.0 | |
Ibm Financial Transaction Manager | =3.0.0 | |
Ibm Financial Transaction Manager | =3.0.2 | |
Ibm Financial Transaction Manager | =3.0.2 | |
Ibm Financial Transaction Manager | =3.0.5 | |
Ibm Financial Transaction Manager | =3.0.6 | |
Ibm Financial Transaction Manager | =3.1.0 | |
Ibm Financial Transaction Manager | =3.2.1 | |
Ibm Financial Transaction Manager | =3.2.2 | |
Ibm Financial Transaction Manager | =3.2.3 | |
Ibm Financial Transaction Manager | =3.2.4 | |
Ibm Financial Transaction Manager | =3.2.4 | |
Ibm Financial Transaction Manager | =3.2.4 | |
IBM Financial Transaction Manager for Corporate Payment Services for MP | <=3.2.4 | |
IBM Financial Transaction Manager for Corporate Payment Services for MP | <=3.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2020-4555.
CVE-2020-4555 has a severity level of medium.
CVE-2020-4555 affects IBM Financial Transaction Manager versions 2.1.1.0, 3.0.0, 3.0.2, 3.0.5, 3.0.6, 3.1.0, 3.2.1, 3.2.2, 3.2.3, 3.2.4.
CVE-2020-4555 allows an authenticated user to impersonate another user on the system due to session not being invalidated after logout.
Yes, you can find more information about CVE-2020-4555 at the following links: [1] [2] [3].