First published: Fri Jul 31 2020(Updated: )
IBM Financial Transaction Manager 3.2.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ibm Financial Transaction Manager | =3.2.4.0 | |
<=3.2.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-4560.
CVE-2020-4560 has a severity rating of 6.1 (medium).
An attacker can exploit this vulnerability by embedding arbitrary JavaScript code in the Web UI to alter the intended functionality and potentially disclose credentials within a trusted session.
Yes, a patch is available for IBM Financial Transaction Manager 3.2.4. You can download it from the IBM Support website.
You can find more information about CVE-2020-4560 on the IBM X-Force Exchange website and the IBM Support pages.