XML External Entity Injection in IBM Financial Transaction Manager
CVE-2020-5003

6.5MEDIUM

Key Information:

Vendor

IBM

Vendor
CVE Published:
11 June 2021

What is CVE-2020-5003?

IBM Financial Transaction Manager 3.2.4 is susceptible to an XML External Entity Injection (XXE) attack, which occurs during the processing of XML data. This vulnerability allows remote attackers to exploit the system, potentially leading to the exposure of sensitive information or the exhaustion of memory resources. Such attacks can have serious implications for data integrity and confidentiality, highlighting the importance of prompt security measures.

Affected Version(s)

Financial Transaction Manager 3.2.4

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.