SQL Injection Vulnerability in IBM Financial Transaction Manager for Digital Payments
CVE-2019-4575

5.3MEDIUM

Key Information:

Vendor
IBM
Vendor
CVE Published:
15 June 2022

Summary

IBM Financial Transaction Manager for Digital Payments versions 3.2.0 through 3.2.9 are susceptible to SQL injection attacks. By exploiting this vulnerability, a remote attacker can execute specially-crafted SQL queries, potentially leading to unauthorized access to the backend database. This may allow the attacker to view, modify, or delete critical information, posing significant risks to data integrity and security.

Affected Version(s)

Financial Transaction Manager 3.2.0

Financial Transaction Manager 3.2.9

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.