CVE-2020-4555
CVE-2020-4555
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 6.3EPSS 0.8%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
21 Dec 2020Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
IBM Financial Transaction Manager 3.0.6 and 3.1.0 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 183328.
CVSS:3.0/S:U/UI:N/AV:N/PR:L/AC:L/I:L/C:L/A:L/E:U/RL:O/RC:C
Affected products
IBM · Financial Transaction ManagerReferences
https://exchange.xforce.ibmcloud.com/vulnerabilities/183328https://www.ibm.com/support/pages/node/6388702https://www.ibm.com/support/pages/node/6388704https://www.ibm.com/support/pages/node/6388706https://www.ibm.com/support/pages/node/6388708https://www.ibm.com/support/pages/node/6388722https://www.ibm.com/support/pages/node/6388744