CVE-2022-43872

IBM Financial Transaction Manager 3.2.4 authorization checks are done incorrectly for some HTTP requests which allows getting unauthorized technical information (e.g. event log entries) about the FTM SWIFT system. IBM X-Force ID: 239708.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:ibm:financial_transaction_manager:3.2.4:*:*:*:*:swift_services:*:*
OR cpe:2.3:o:ibm:aix:-:*:*:*:*:*:*:*
cpe:2.3:o:ibm:linux_on_ibm_z:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*

History

07 Nov 2023, 03:54

Type Values Removed Values Added
Summary IBM Financial Transaction Manager 3.2.4 authorization checks are done incorrectly for some HTTP requests which allows getting unauthorized technical information (e.g. event log entries) about the FTM SWIFT system. IBM X-Force ID: 239708. IBM Financial Transaction Manager 3.2.4 authorization checks are done incorrectly for some HTTP requests which allows getting unauthorized technical information (e.g. event log entries) about the FTM SWIFT system. IBM X-Force ID: 239708.

14 Feb 2023, 15:51

Type Values Removed Values Added
First Time Ibm linux On Ibm Z
CPE cpe:2.3:o:ibm:linux_on_zseries:-:*:*:*:*:*:*:* cpe:2.3:o:ibm:linux_on_ibm_z:-:*:*:*:*:*:*:*

27 Dec 2022, 21:50

Type Values Removed Values Added
References (MISC) https://www.ibm.com/support/pages/node/6848881 - (MISC) https://www.ibm.com/support/pages/node/6848881 - Patch, Vendor Advisory
References (MISC) https://exchange.xforce.ibmcloud.com/vulnerabilities/239708 - (MISC) https://exchange.xforce.ibmcloud.com/vulnerabilities/239708 - VDB Entry, Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.3
First Time Ibm linux On Zseries
Ibm financial Transaction Manager
Ibm aix
Ibm
Linux
Linux linux Kernel
CPE cpe:2.3:o:ibm:aix:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:ibm:linux_on_zseries:-:*:*:*:*:*:*:*
cpe:2.3:a:ibm:financial_transaction_manager:3.2.4:*:*:*:*:swift_services:*:*
CWE CWE-863

20 Dec 2022, 20:38

Type Values Removed Values Added
New CVE

Information

Published : 2022-12-20 19:15

Updated : 2023-12-10 14:48


NVD link : CVE-2022-43872

Mitre link : CVE-2022-43872

CVE.ORG link : CVE-2022-43872


JSON object : View

Products Affected

linux

  • linux_kernel

ibm

  • linux_on_ibm_z
  • aix
  • financial_transaction_manager
CWE
CWE-863

Incorrect Authorization