XML External Entity Injection in IBM Financial Transaction Manager
CVE-2020-5003
6.5MEDIUM
Summary
IBM Financial Transaction Manager 3.2.4 is susceptible to an XML External Entity Injection (XXE) attack, which occurs during the processing of XML data. This vulnerability allows remote attackers to exploit the system, potentially leading to the exposure of sensitive information or the exhaustion of memory resources. Such attacks can have serious implications for data integrity and confidentiality, highlighting the importance of prompt security measures.
Affected Version(s)
Financial Transaction Manager 3.2.4
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved