CVE-2020-5001: IBM Financial Transaction Manager path traversal
IBM Financial Transaction Manager 3.2.0 through 3.2.7 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 192953.
Other sources
IBM Financial Transaction Manager could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this IBM Financial Transaction Manager vulnerability?
The vulnerability ID for this IBM Financial Transaction Manager vulnerability is CVE-2020-5001.
What is the severity rating of CVE-2020-5001?
The severity rating of CVE-2020-5001 is high (7.5).
How does CVE-2020-5001 affect IBM Financial Transaction Manager?
CVE-2020-5001 allows a remote attacker to traverse directories on the system, potentially enabling them to view arbitrary files.
Which versions of IBM Financial Transaction Manager are affected by CVE-2020-5001?
IBM Financial Transaction Manager versions 3.2.0 through 3.2.7 are affected by CVE-2020-5001.
How can I fix CVE-2020-5001 in IBM Financial Transaction Manager?
To fix CVE-2020-5001 in IBM Financial Transaction Manager, apply the appropriate patch or update provided by IBM.