Vulnerability: CVE-2020-4555

IBM Financial Transaction Manager 3.0.6 and 3.1.0 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 183328.


https://www.ibm.com/support/pages/node/6388702
https://www.ibm.com/support/pages/node/6388702
https://www.ibm.com/support/pages/node/6388704
https://www.ibm.com/support/pages/node/6388704
https://www.ibm.com/support/pages/node/6388706
https://www.ibm.com/support/pages/node/6388706
https://www.ibm.com/support/pages/node/6388708
https://www.ibm.com/support/pages/node/6388708
https://www.ibm.com/support/pages/node/6388722
https://www.ibm.com/support/pages/node/6388722
https://www.ibm.com/support/pages/node/6388744
https://www.ibm.com/support/pages/node/6388744
https://exchange.xforce.ibmcloud.com/vulnerabilities/183328
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-4555


It's possible to leave a comment as registered users to the site, accessing through social, wordpress account or as anonymous users. If you want to leave a comment as an anonymous user you will be notified by email of a possible response only if you enter the email address (optional). The insertion of any data in the comment fields is totally optional. Whoever decides to insert any data accepts the treatment of these last ones for the inherent purposes of the service that is the answer to the comment and the strictly necessary communications.


Leave a Reply