Vulnerabilities > CVE-2022-43872 - Incorrect Authorization vulnerability in IBM Financial Transaction Manager 3.2.4

047910
CVSS 5.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
LOW
Integrity impact
NONE
Availability impact
NONE
network
low complexity
ibm
CWE-863

Summary

IBM Financial Transaction Manager 3.2.4 authorization checks are done incorrectly for some HTTP requests which allows getting unauthorized technical information (e.g. event log entries) about the FTM SWIFT system. IBM X-Force ID: 239708.

Vulnerable Configurations

Part Description Count
Application
Ibm
1
OS
Ibm
2
OS
Linux
1

Common Weakness Enumeration (CWE)