Information Disclosure in IBM Financial Transaction Manager for Digital Payments
CVE-2020-5026
4.3MEDIUM
Summary
The IBM Financial Transaction Manager for Digital Payments presents a vulnerability where a remote attacker may gain access to sensitive information. This can occur when detailed technical error messages are displayed in a web browser, potentially allowing attackers to leverage this information for further system exploitation. Proper handling of error messages is essential to prevent the inadvertent exposure of critical data.
Affected Version(s)
Financial Transaction Manager 3.2.0 < 3.2.7
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved