Description
IBM Financial Transaction Manager for Digital Payments for Multi-Platform 3.0.2, 3.0.4, 3.0.6, and 3.2.0 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-force ID: 150023.
CVSS breakdown
CVSS 3.0
Availability
Low
Attack Complexity
Low
Attack Vector
Network
Confidentiality
Low
Integrity
Low
Privileges Required
Low
Scope
Unchanged
User Interaction
None
E
Unchanged
RC
Changed
RL
O
Affected products
- ibm / Financial Transaction Manager3.0.2 – 3.0.2
- ibm / Financial Transaction Manager3.0.4 – 3.0.4
- ibm / Financial Transaction Manager3.0.6 – 3.0.6
- ibm / Financial Transaction Manager3.2.0 – 3.2.0
- ibm / Financial Transaction Manager3.2.0.0 – 3.2.0.0