CVE Published: 14/04/2017 |
CVE Updated: 05/08/2024 |
CVE Year: 2017 Source: ibm |
Vendor: IBM Corporation |
Product: Financial Transaction Manager Status : PUBLISHED
CVE-2017-1152 Description
IBM Financial Transaction Manager 3.0.1 and 3.0.2 does not properly update the SESSIONID with each request, which could allow a user to obtain the ID in further attacks against the system. IBM X-Force ID: 122293.