Information Disclosure in IBM Financial Transaction Manager for Digital Payments
CVE-2020-5026

4.3MEDIUM

Key Information:

Vendor
IBM
Vendor
CVE Published:
1 March 2023

Summary

The IBM Financial Transaction Manager for Digital Payments presents a vulnerability where a remote attacker may gain access to sensitive information. This can occur when detailed technical error messages are displayed in a web browser, potentially allowing attackers to leverage this information for further system exploitation. Proper handling of error messages is essential to prevent the inadvertent exposure of critical data.

Affected Version(s)

Financial Transaction Manager 3.2.0 < 3.2.7

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.