CVE-2020-4560: XSS
IBM Financial Transaction Manager 3.2.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Other sources
IBM Financial Transaction Manager is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for the cross-site scripting vulnerability in IBM Financial Transaction Manager?
The vulnerability ID is CVE-2020-4560.
What is the severity rating of CVE-2020-4560?
CVE-2020-4560 has a severity rating of 6.1 (medium).
How can an attacker exploit this vulnerability?
An attacker can exploit this vulnerability by embedding arbitrary JavaScript code in the Web UI to alter the intended functionality and potentially disclose credentials within a trusted session.
Is there a patch available for IBM Financial Transaction Manager 3.2.4?
Yes, a patch is available for IBM Financial Transaction Manager 3.2.4. You can download it from the IBM Support website.
Where can I find more information about CVE-2020-4560?
You can find more information about CVE-2020-4560 on the IBM X-Force Exchange website and the IBM Support pages.