CVE-2016-3060 Information

Description

Payments Director in IBM Financial Transaction Manager (FTM) for ACH Services Check Services and Corporate Payment Services (CPS) 3.0.0.x before fp0015 and 3.0.1.0 before iFix0002 allows remote authenticated users to conduct clickjacking attacks via a crafted web site.

CVSS Vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N

Reference

http://www.securityfocus.com/bid/92633 http://www-01.ibm.com/support/docview.wss?uid=swg1PI64063 http://www-01.ibm.com/support/docview.wss?uid=swg1PI64064 http://www-01.ibm.com/support/docview.wss?uid=swg1PI67537 http://www-01.ibm.com/support/docview.wss?uid=swg21989060

Attack Complexity

LOW

Privileges Required

LOW

User Interaction Required

LOW

Scope

REQUIRED

Confidentiality Impact

UNCHANGED

Integrity Impact

NONE

Availability Impact

HIGH

Base Score

NONE

Base Severity

5.7

Share on: