CVE-2018-1871
Description
IBM Financial Transaction Manager for Digital Payments for Multi-Platform 3.0.0, 3.0.2, and 3.0.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 151329.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
IBM Financial Transaction Manager for Digital Payments is vulnerable to stored cross-site scripting, allowing attackers to inject arbitrary JavaScript into the Web UI and potentially steal credentials.
Vulnerability
IBM Financial Transaction Manager for Digital Payments for Multi-Platform versions 3.0.0.0 through 3.0.0.15, 3.0.2.0 through 3.0.2.1, and 3.0.5.0 through 3.0.5.1 contain a stored cross-site scripting (XSS) vulnerability. The flaw exists in the Web UI, where user-supplied input is not properly sanitized before being stored and later rendered in the context of an authenticated session [1]. This allows users with low-privileged access to embed arbitrary JavaScript code into pages viewed by other users.
Exploitation
An attacker with a low-privileged account on the affected system can inject malicious script code through input fields in the Web UI. The injected script is stored on the server and executed automatically when a higher-privileged user (or any user) views the affected page. No special network position or additional user interaction beyond normal page viewing is required, though the attacker must have a valid authenticated session to perform the injection [1].
Impact
Successful exploitation allows the attacker to execute arbitrary JavaScript in the context of the victim's browser session. This can alter intended UI functionality and lead to disclosure of sensitive credentials within the trusted session, potentially enabling account takeover or unauthorized transactions [1]. The CVSS v3.0 base score is 5.4 (medium), with the scope changed and partial loss of confidentiality and integrity [1].
Mitigation
IBM has released fixes as detailed in security bulletin 10743123 [1]. Affected installations should upgrade to the latest patched versions for FTM CHK v3.0.0, v3.0.2, and v3.0.5. No workarounds are provided in the advisory. The vulnerability is not listed on CISA's Known Exploited Vulnerabilities (KEV) catalog.
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: 3.0.0, 3.0.2, 3.0.5
- Range: 3.0.2
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- www.ibm.com/support/docview.wssmitrex_refsource_CONFIRM
- www.securityfocus.com/bid/106149mitrevdb-entryx_refsource_BID
- exchange.xforce.ibmcloud.com/vulnerabilities/151329mitrevdb-entryx_refsource_XF
News mentions
0No linked articles in our index yet.