Vulnerabilities > IBM > Transformation Extender Advanced

DATE CVE VULNERABILITY TITLE RISK
2021-10-21 CVE-2021-29883 Missing Encryption of Sensitive Data vulnerability in IBM Transformation Extender Advanced
IBM Standards Processing Engine (IBM Transformation Extender Advanced 9.0 and 10.0) does not set the secure attribute on authorization tokens or session cookies.
network
low complexity
ibm CWE-311
4.3
2018-02-21 CVE-2017-1758 XXE vulnerability in IBM products
IBM Financial Transaction Manager for ACH Services for Multi-Platform (IBM Control Center 6.0 and 6.1, IBM Financial Transaction Manager 3.0.2, 3.0.3, 3.0.4, and 3.1.0, IBM Transformation Extender Advanced 9.0) is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data.
network
low complexity
ibm CWE-611
7.1