Vulnerability Name: CVE-2018-1819 (CCN-150023) Assigned: 2017-12-13 Published: 2018-10-02 Updated: 2019-10-09 Summary: IBM Financial Transaction Manager for Digital Payments for Multi-Platform 3.0.2, 3.0.4, 3.0.6, and 3.2.0 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-force ID: 150023. CVSS v3 Severity: 8.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H )7.7 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C )Exploitability Metrics: Attack Vector (AV): NetworkAttack Complexity (AC): LowPrivileges Required (PR): LowUser Interaction (UI): NoneScope: Scope (S): UnchangedImpact Metrics: Confidentiality (C): HighIntegrity (I): HighAvailibility (A): High
6.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L )5.5 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:U/RL:O/RC:C )Exploitability Metrics: Attack Vector (AV): NetworkAttack Complexity (AC): LowPrivileges Required (PR): LowUser Interaction (UI): NoneScope: Scope (S): UnchangedImpact Metrics: Confidentiality (C): LowIntegrity (I): LowAvailibility (A): Low
CVSS v2 Severity: 6.5 Medium (CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): LowAuthentication (Au): Single_InstanceImpact Metrics: Confidentiality (C): PartialIntegrity (I): PartialAvailibility (A): Partial
6.5 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): LowAthentication (Au): Single_InstanceImpact Metrics: Confidentiality (C): PartialIntegrity (I): PartialAvailibility (A): Partial
Vulnerability Type: CWE-89 Vulnerability Consequences: Data Manipulation References: Source: MITRE Type: CNACVE-2018-1819 Source: CCN Type: IBM Security Bulletin 732357 (Financial Transaction Manager)Financial Transaction Manager for Digital Payments for Multi-Platform is affected by a potential SQL Injection vulnerability CVE-2018-1819 Source: CONFIRM Type: Patch, Vendor Advisoryhttp://www.ibm.com/support/docview.wss?uid=ibm10732357 Source: CCN Type: IBM Security Bulletin 732361 (Financial Transaction Manager)Financial Transaction Manager for ACH Services for Multi-Platform is affected by a potential SQL Injection vulnerability CVE-2018-1819 Source: CONFIRM Type: Patch, Vendor Advisoryhttp://www.ibm.com/support/docview.wss?uid=ibm10732361 Source: CCN Type: IBM Security Bulletin 732367 (Financial Transaction Manager)Financial Transaction Manager for Corporate Payment Services for Multi-Platform is affected by a potential SQL Injection vulnerability CVE-2018-1819 Source: CONFIRM Type: Patch, Vendor Advisoryhttp://www.ibm.com/support/docview.wss?uid=ibm10732367 Source: XF Type: UNKNOWNibm-ftm-cve20181819-sql-injection(150023) Source: XF Type: VDB Entry, Vendor Advisoryibm-ftm-cve20181819-sql-injection(150023) Source: CCN Type: IBM Security Bulletin 732371 (Financial Transaction Manager)Financial Transaction Manager for Corporate Payment Services for Multi-Platform v2.1.1 is affected by a potential SQL Injection vulnerability CVE-2018-1819 Vulnerable Configuration: Configuration 1 :cpe:/a:ibm:financial_transaction_manager:3.0.2.0:*:*:*:*:cps_services:*:* OR cpe:/a:ibm:financial_transaction_manager:3.0.2.1:*:*:*:*:cps_services:*:* OR cpe:/a:ibm:financial_transaction_manager:3.0.4.0:*:*:*:*:cps_services:*:* OR cpe:/a:ibm:financial_transaction_manager:3.0.6.0:*:*:*:*:ach_services:*:* OR cpe:/a:ibm:financial_transaction_manager:3.0.6.1:*:*:*:*:ach_services:*:* OR cpe:/a:ibm:financial_transaction_manager:3.1.0.0:*:*:*:*:ach_services:*:* OR cpe:/a:ibm:financial_transaction_manager:3.1.0.1:*:*:*:*:ach_services:*:* OR cpe:/a:ibm:financial_transaction_manager:3.1.0.2:*:*:*:*:ach_services:*:* OR cpe:/a:ibm:financial_transaction_manager:3.2.0.0:*:*:*:*:digital_payments:*:* Configuration CCN 1 :cpe:/a:ibm:financial_transaction_manager:3.0.2.0:*:*:*:*:ach_services:*:* OR cpe:/a:ibm:financial_transaction_manager:3.0.4.0::~~~cps_services~~:*:*:*:*:* OR cpe:/a:ibm:financial_transaction_manager:3.0.6.0::~~~ach_services~~:*:*:*:*:* OR cpe:/a:ibm:financial_transaction_manager:3.2.0.0::~~~digital_payments~~:*:*:*:*:* OR cpe:/a:ibm:financial_transaction_manager:3.2.0.0:*:*:*:*:digital_payments:*:* AND cpe:/a:ibm:financial_transaction_manager:2.1.1.0:*:*:*:*:*:*:* Denotes that component is vulnerable BACK
ibm financial transaction manager 3.0.2.0
ibm financial transaction manager 3.0.2.1
ibm financial transaction manager 3.0.4.0
ibm financial transaction manager 3.0.6.0
ibm financial transaction manager 3.0.6.1
ibm financial transaction manager 3.1.0.0
ibm financial transaction manager 3.1.0.1
ibm financial transaction manager 3.1.0.2
ibm financial transaction manager 3.2.0.0
ibm financial transaction manager 3.0.2.0
ibm financial transaction manager 3.0.4.0
ibm financial transaction manager 3.0.6.0
ibm financial transaction manager 3.2.0.0
ibm financial transaction manager 3.2.0.0
ibm financial transaction manager 2.1.1.0