VYPR
Medium severity5.4NVD Advisory· Published Dec 21, 2020· Updated Jun 17, 2026

CVE-2020-4555

CVE-2020-4555

Description

IBM Financial Transaction Manager 3.0.6 and 3.1.0 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 183328.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

15
  • cpe:2.3:a:ibm:financial_transaction_manager:2.1.1.0:*:*:*:*:cps_services:*:*+ 14 more
    • cpe:2.3:a:ibm:financial_transaction_manager:2.1.1.0:*:*:*:*:cps_services:*:*
    • cpe:2.3:a:ibm:financial_transaction_manager:3.0.0:*:*:*:*:check_services:*:*
    • cpe:2.3:a:ibm:financial_transaction_manager:3.0.2:*:*:*:*:check_services:*:*
    • cpe:2.3:a:ibm:financial_transaction_manager:3.0.2:*:*:*:*:cps_services:*:*
    • cpe:2.3:a:ibm:financial_transaction_manager:3.0.5:*:*:*:*:check_services:*:*
    • cpe:2.3:a:ibm:financial_transaction_manager:3.0.6:*:*:*:*:ach_services:*:*
    • cpe:2.3:a:ibm:financial_transaction_manager:3.1.0:*:*:*:*:ach_services:*:*
    • cpe:2.3:a:ibm:financial_transaction_manager:3.2.1:*:*:*:*:cps_services:*:*
    • cpe:2.3:a:ibm:financial_transaction_manager:3.2.2:*:*:*:*:digital_payments:*:*
    • cpe:2.3:a:ibm:financial_transaction_manager:3.2.3:*:*:*:*:digital_payments:*:*
    • cpe:2.3:a:ibm:financial_transaction_manager:3.2.4:*:*:*:*:cps_services:*:*
    • cpe:2.3:a:ibm:financial_transaction_manager:3.2.4:*:*:*:*:digital_payments:*:*
    • cpe:2.3:a:ibm:financial_transaction_manager:3.2.4:*:*:*:*:high_value:*:*
    • (no CPE)range: 3.0.6, 3.1.0
    • (no CPE)range: 3.0.2

Patches

Vulnerability mechanics

References

7

News mentions

0

No linked articles in our index yet.