First published: Mon Aug 30 2021(Updated: )
IBM Financial Transaction Manager 3.2.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 205045.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Financial Transaction Manager for SWIFT Services for Multiplatforms | <=3.2.4 | |
IBM Financial Transaction Manager for SWIFT Services for Multiplatforms | =3.2.4 | |
IBM AIX | ||
Ibm Linux On Ibm Z | ||
Ibm Z\/os | ||
Linux Linux kernel |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-29841 is a vulnerability in IBM Financial Transaction Manager 3.2.4 that allows users to embed arbitrary JavaScript code in the Web UI, potentially leading to credentials disclosure within a trusted session.
CVE-2021-29841 has a severity rating of 5.4 out of 10 (medium).
CVE-2021-29841 affects IBM Financial Transaction Manager 3.2.4 by allowing cross-site scripting, which can alter the intended functionality and potentially lead to credentials disclosure.
The CWE ID for CVE-2021-29841 is 79 (Cross-site Scripting).
To fix CVE-2021-29841, it is recommended to update IBM Financial Transaction Manager to a patched version provided by IBM.