First published: Mon Feb 27 2023(Updated: )
IBM Financial Transaction Manager for Digital Payments for Multi-Platform 3.2.0 through 3.2.7 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 193662.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ibm Financial Transaction Manager | >=3.2.0.0<=3.2.7 | |
IBM Financial Transaction Manager for Corporate Payment Services for Multi-Platform | <=3.2.0-3.2.10 | |
IBM Financial Transaction Manager for Digital Payments for Multi-Platform | <=3.2.0-3.2.10 | |
IBM Financial Transaction Manager for High Value Payments for Multi-Platform | <=3.2.0-3.2.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-5026 is a vulnerability in IBM Financial Transaction Manager for Digital Payments for Multi-Platform that could allow a remote attacker to obtain sensitive information.
The vulnerability exists in the software version 3.2.0 through 3.2.7 of IBM Financial Transaction Manager for Digital Payments for Multi-Platform.
CVE-2020-5026 has a severity score of 7.5, which is considered high.
A remote attacker can exploit CVE-2020-5026 to obtain sensitive information when a detailed technical error message is returned in the browser.
To fix CVE-2020-5026, you can apply the patch provided by IBM or upgrade to a version that is not affected.