First published: Mon Jan 31 2022(Updated: )
IBM Financial Transaction Manager 3.2.4 does not invalidate session any existing session identifier gives an attacker the opportunity to steal authenticated sessions. IBM X-Force ID: 215040.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Financial Transaction Manager for SWIFT Services for Multiplatforms | <=3.2.4 | |
Ibm Financial Transaction Manager | =3.2.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-39066 is a vulnerability in IBM Financial Transaction Manager 3.2.4 that allows an attacker to steal authenticated sessions by using any existing session identifier.
The severity of CVE-2021-39066 is high with a CVSS score of 8.8.
CVE-2021-39066 affects IBM Financial Transaction Manager 3.2.4 by not invalidating sessions, allowing an attacker to steal authenticated sessions.
Yes, IBM has provided fixes for CVE-2021-39066. Please refer to the IBM support page for more information.
You can find more information about CVE-2021-39066 on the IBM X-Force ID 215040 and the IBM support page.