Cross-Site Scripting Vulnerability in IBM Financial Transaction Manager
CVE-2020-5000
5.4MEDIUM
What is CVE-2020-5000?
IBM Financial Transaction Manager versions 3.2.0 through 3.2.8 are exposed to a cross-site scripting flaw that allows an attacker to inject arbitrary JavaScript into the application’s web interface. This security weakness can potentially alter the intended functionalities of the application, enabling unauthorized actions within users' sessions, which may lead to the disclosure of sensitive credentials.
Affected Version(s)
Financial Transaction Manager 3.2.0 < 3.2.8