CVE-2021-29841: XSS
IBM Financial Transaction Manager 3.2.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 205045.
Other sources
IBM Financial Transaction Manager is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-29841?
CVE-2021-29841 is a vulnerability in IBM Financial Transaction Manager 3.2.4 that allows users to embed arbitrary JavaScript code in the Web UI, potentially leading to credentials disclosure within a trusted session.
How severe is CVE-2021-29841?
CVE-2021-29841 has a severity rating of 5.4 out of 10 (medium).
How does CVE-2021-29841 affect IBM Financial Transaction Manager?
CVE-2021-29841 affects IBM Financial Transaction Manager 3.2.4 by allowing cross-site scripting, which can alter the intended functionality and potentially lead to credentials disclosure.
What is the CWE ID for this vulnerability?
The CWE ID for CVE-2021-29841 is 79 (Cross-site Scripting).
How can I fix CVE-2021-29841?
To fix CVE-2021-29841, it is recommended to update IBM Financial Transaction Manager to a patched version provided by IBM.