CVE-2021-39044: CSRF
IBM Financial Transaction Manager 3.2.4 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 214210.
Other sources
IBM Financial Transaction Manager is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-39044?
CVE-2021-39044 is a vulnerability in IBM Financial Transaction Manager 3.2.4 that allows an attacker to execute malicious actions transmitted from a trusted user.
How severe is CVE-2021-39044?
CVE-2021-39044 has a severity rating of 8.8, which is considered high.
How does CVE-2021-39044 affect IBM Financial Transaction Manager?
CVE-2021-39044 affects IBM Financial Transaction Manager 3.2.4 by making it vulnerable to cross-site request forgery attacks.
How can an attacker exploit CVE-2021-39044?
An attacker can exploit CVE-2021-39044 by tricking a trusted user into performing malicious actions on behalf of the attacker.
Is there a fix for CVE-2021-39044?
Yes, IBM has provided a fix for CVE-2021-39044. It is recommended to update to the latest version of IBM Financial Transaction Manager.