CVE-2020-5002: IBM Financial Transaction Manager security bypass
IBM Financial Transaction Manager 3.2.0 through 3.2.10 could allow an authenticated user to perform unauthorized actions due to improper validation. IBM X-Force ID: 192954.
Other sources
IBM Financial Transaction Manager could allow an authenticated user to perform unauthorized actions due to improper validation.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2020-5002.
What is the severity of CVE-2020-5002?
The severity of CVE-2020-5002 is high with a score of 8.8.
Which software versions are affected by CVE-2020-5002?
IBM Financial Transaction Manager versions 3.2.0 through 3.2.10 are affected by CVE-2020-5002.
How can I fix CVE-2020-5002?
You can fix CVE-2020-5002 by applying the patch provided by IBM. Please refer to the following URL for the patch: [https://www.ibm.com/support/pages/download-ibm-financial-transaction-manager-corporate-payment-services-multiplatforms-v3211](https://www.ibm.com/support/pages/download-ibm-financial-transaction-manager-corporate-payment-services-multiplatforms-v3211).
What is the Common Weakness Enumeration (CWE) ID for CVE-2020-5002?
The Common Weakness Enumeration (CWE) ID for CVE-2020-5002 is CWE-20.