Payments Director in IBM Financial Transaction Manager (FTM) for ACH Services, Check Services, and Corporate Payment Services (CPS) 3.0.0.x before fp0015 and 3.0.1.0 before iFix0002 allows remote authenticated users to conduct clickjacking attacks via a crafted web site.
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Link | Tags |
---|---|
http://www-01.ibm.com/support/docview.wss?uid=swg1PI64064 | vendor advisory not applicable |
http://www-01.ibm.com/support/docview.wss?uid=swg1PI64063 | vendor advisory not applicable |
http://www-01.ibm.com/support/docview.wss?uid=swg21989060 | patch vendor advisory |
http://www-01.ibm.com/support/docview.wss?uid=swg1PI67537 | vendor advisory not applicable |
http://www.securityfocus.com/bid/92633 | vdb entry |