CVE-2020-4555
21.12.2020, 18:15
IBM Financial Transaction Manager 3.0.6 and 3.1.0 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 183328.Enginsight
| Vendor | Product | Version |
|---|---|---|
| ibm | financial_transaction_manager | 2.1.1.0 |
| ibm | financial_transaction_manager | 3.0.0 |
| ibm | financial_transaction_manager | 3.0.2 |
| ibm | financial_transaction_manager | 3.0.2 |
| ibm | financial_transaction_manager | 3.0.5 |
| ibm | financial_transaction_manager | 3.0.6 |
| ibm | financial_transaction_manager | 3.1.0 |
| ibm | financial_transaction_manager | 3.2.1 |
| ibm | financial_transaction_manager | 3.2.2 |
| ibm | financial_transaction_manager | 3.2.3 |
| ibm | financial_transaction_manager | 3.2.4 |
| ibm | financial_transaction_manager | 3.2.4 |
| ibm | financial_transaction_manager | 3.2.4 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References