First published: Tue Dec 15 2020(Updated: )
IBM Financial Transaction Manager for SWIFT Services could allow an remote attacker to obtain sensitive information, caused by a man in the middle attack. By SSL striping, an attacker could exploit this vulnerability to to obtain sensitive information.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
=3.2.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-4905 is a vulnerability in IBM Financial Transaction Manager for SWIFT Services that allows a remote attacker to obtain sensitive information by exploiting a man-in-the-middle attack through SSL stripping.
The severity of CVE-2020-4905 is medium with a CVSS score of 5.9.
IBM Financial Transaction Manager for Multiplatforms version 3.2.4 is affected by CVE-2020-4905.
An attacker can exploit CVE-2020-4905 by performing a man-in-the-middle attack and using SSL stripping to intercept and obtain sensitive information.
To fix CVE-2020-4905, IBM Financial Transaction Manager for SWIFT Services should be updated to a version that patches the vulnerability.