CVE-2017-1152
14.04.2017, 16:59
IBM Financial Transaction Manager 3.0.1 and 3.0.2 does not properly update the SESSIONID with each request, which could allow a user to obtain the ID in further attacks against the system. IBM X-Force ID: 122293.Enginsight
Vendor | Product | Version |
---|---|---|
ibm | financial_transaction_manager | 3.0.1.0 |
ibm | financial_transaction_manager | 3.0.1.0 |
ibm | financial_transaction_manager | 3.0.2.0 |
ibm | financial_transaction_manager | 3.0.2.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration