Vulnerabilities (CVE)

Filtered by vendor Ibm Subscribe
Filtered by product Transformation Extender Advanced
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-29883 1 Ibm 1 Transformation Extender Advanced 2023-12-10 4.3 MEDIUM 4.3 MEDIUM
IBM Standards Processing Engine (IBM Transformation Extender Advanced 9.0 and 10.0) does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. IBM X-Force ID: 207090.
CVE-2017-1758 1 Ibm 3 Control Center, Financial Transaction Manager, Transformation Extender Advanced 2023-12-10 5.5 MEDIUM 7.1 HIGH
IBM Financial Transaction Manager for ACH Services for Multi-Platform (IBM Control Center 6.0 and 6.1, IBM Financial Transaction Manager 3.0.2, 3.0.3, 3.0.4, and 3.1.0, IBM Transformation Extender Advanced 9.0) is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 135859.