Medium Severity

IBM Security Bulletin: Financial Transaction Manager for Digital Payments is affected by a potential cross-site scripting (XSS) vulnerability (CVE-2018-15494)

Share this post:

Financial Transaction Manager for Digital Payments (FTM DP) for Multi-Platform has addressed the following vulnerability. A potential cross-site scripting vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

CVE(s): CVE-2018-15494

Affected product(s) and affected version(s):

FTM DP v3.2.0.0 – v3.2.0.1, v3.2.2.0

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: https://www-01.ibm.com/support/docview.wss?uid=ibm10795504
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/148556

More stories

IBM Security Bulletin: A security vulnerability has been identified in WebSphere Application Server shipped with IBM Cloud Orchestrator and IBM Cloud Orchestrator Enterprise (CVE-2018-1996)

Oct 21, 2019 9:01 am EDT | Medium Severity

WebSphere Application Server is shipped with IBM Cloud Orchestrator and IBM Cloud Orchestrator Enterprise. Information about a security vulnerability affecting WebSphere Application Server has been published in a security bulletin. CVE(s): CVE-2018-1996 Affected product(s) and affected version(s): Affected Product Name Affected Versions IBM Cloud Orchestrator and IBM Cloud Orchestrator Enterprise Edition V2.5, V2.5.0.1, V2.5.02. V2.5.0.3, ...read more


IBM Security Bulletin: IBM FileNet Content Manager and Case Foundation security vulnerability in Process Orchestration Web Service logging

Oct 11, 2019 9:02 am EDT | Medium Severity

A security vulnerability in IBM FileNet Content Manager and Case Foundation, in some case, could contain user information in the log when Process Orchestration Web Services is invoked. CVE(s): CVE-2019-4572 Affected product(s) and affected version(s): FileNet Content Manager and Case Foundation 5.5.2, 5.5.3. This security vulnerability only exists in 5.5.2.0-P8CPE-IF001, 5.5.2.0-P8CPE-IF002 and 5.5.3.0-P8CPE (GA). Refer ...read more


IBM Security Bulletin: IBM FileNet Content Manager and Case Foundation are affected by Publicly disclosed vulnerability in Java July 2019

Oct 11, 2019 9:02 am EDT | Medium Severity

IBM FileNet Content Manager and Case Foundation has addressed the following vulnerabilities in versions 5.5.2 and 5.5.3. CVE(s): CVE-2019-2762, CVE-2019-2769 Affected product(s) and affected version(s): FileNet Content Manager and Case Foundation 5.5.2, 5.5.3 Refer to the following reference URLs for remediation and additional vulnerability details:Source Bulletin: https://supportcontent.ibm.com/support/pages/node/967409X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/163826X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/163832 ...read more