First published: Tue Dec 15 2020(Updated: )
IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ibm Financial Transaction Manager For Multiplatform | =3.2.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2020-4904.
The severity of CVE-2020-4904 is medium.
CVE-2020-4904 is a vulnerability in IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4 that allows an attacker to execute malicious actions transmitted from a trusted user.
An attacker can exploit CVE-2020-4904 through cross-site request forgery, tricking a user into executing unauthorized actions on the website.
Yes, IBM has provided a fix for CVE-2020-4904. Please refer to the IBM support page for more information.