IBM Financial Transaction Manager 3.0.6 and 3.1.0 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 183328.
2020-12-21T18:15:15.820
2024-11-21T05:32:53.810
Modified
CVSSv3.1: 5.4 (MEDIUM)
AV:N/AC:L/Au:S/C:P/I:P/A:N
8.0
4.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | ibm | financial_transaction_manager | 2.1.1.0 | Yes |
Application | ibm | financial_transaction_manager | 3.0.0 | Yes |
Application | ibm | financial_transaction_manager | 3.0.2 | Yes |
Application | ibm | financial_transaction_manager | 3.0.2 | Yes |
Application | ibm | financial_transaction_manager | 3.0.5 | Yes |
Application | ibm | financial_transaction_manager | 3.0.6 | Yes |
Application | ibm | financial_transaction_manager | 3.1.0 | Yes |
Application | ibm | financial_transaction_manager | 3.2.1 | Yes |
Application | ibm | financial_transaction_manager | 3.2.2 | Yes |
Application | ibm | financial_transaction_manager | 3.2.3 | Yes |
Application | ibm | financial_transaction_manager | 3.2.4 | Yes |
Application | ibm | financial_transaction_manager | 3.2.4 | Yes |
Application | ibm | financial_transaction_manager | 3.2.4 | Yes |