Permissions, Privileges, and Access Controls in Financial Transaction Manager - CVE-2014-0833
Published: February 1, 2014 / Updated: August 10, 2020
Financial Transaction Manager
Detailed vulnerability description
The vulnerability allows a remote #AU# to read and manipulate data.
The OAC component in IBM Financial Transaction Manager (FTM) 2.0 before 2.0.0.3 does not properly enforce operator-intervention requirements, which allows remote authenticated users to bypass intended access restrictions via an unspecified process step.