CVE-2020-4555

MEDIUM

IBM Financial Transaction Manager <3.1.0 - Privilege Escalation

Title source: llm
STIX 2.1

Description

IBM Financial Transaction Manager 3.0.6 and 3.1.0 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 183328.

Scores

CVSS v3 5.4
EPSS 0.0026
EPSS Percentile 49.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

Details

CWE
CWE-384
Status published
Products (10)
ibm/financial_transaction_manager 2.1.1.0
ibm/financial_transaction_manager 3.0.0
ibm/financial_transaction_manager 3.0.2 (2 CPE variants)
ibm/financial_transaction_manager 3.0.5
ibm/financial_transaction_manager 3.0.6
ibm/financial_transaction_manager 3.1.0
ibm/financial_transaction_manager 3.2.1
ibm/financial_transaction_manager 3.2.2
ibm/financial_transaction_manager 3.2.3
ibm/financial_transaction_manager 3.2.4 (3 CPE variants)
Published Dec 21, 2020
Tracked Since Feb 18, 2026