← Vulnerability feed

Vulnerability record · CVE-2020-5003 · published 11 June 2021

CVE-2020-5003: Ibm financial transaction manager xml external entity (xxe) vulnerability

Ibm · Financial Transaction Manager

IBM Financial Transaction Manager 3.2.4 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 192956.

9.1 CVSS 3.1 Critical EPSS 1.8% · top 21.9% CWE-611 · XML external entity (XXE)
9.1CVSS 3.1 base score, v2 6.4
1.8%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

IBM Financial Transaction Manager 3.2.4 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 192956.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-5003 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-4575Ibm financial transaction manager sql injection vulnerabilityIBM Financial Transaction Manager for Digital Payments for Multi-Platform 3.2.0 through 3.2.9 is vulnerable to SQL injection. A remote attacker could…EPSS 1.1%9.8CVE-2019-4032Ibm financial transaction manager sql injection vulnerabilityIBM Financial Transaction Manager for Digital Payments for Multi-Platform 3.1.0 is vulnerable to SQL injection. A remote attacker could send speciall…EPSS 1.6%9.1CVE-2023-35892Ibm financial transaction manager xml external entity (xxe) vulnerabilityIBM Financial Transaction Manager for SWIFT Services 3.2.4 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A…EPSS 1.1%8.8CVE-2020-5002Ibm financial transaction manager improper input validation vulnerabilityIBM Financial Transaction Manager 3.2.0 through 3.2.10 could allow an authenticated user to perform unauthorized actions due to improper validation. …EPSS 0.58%8.8CVE-2021-39044Ibm financial transaction manager cross-site request forgery vulnerabilityIBM Financial Transaction Manager 3.2.4 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthoriz…EPSS 0.38%8.8CVE-2021-39066Ibm financial transaction manager vulnerabilityIBM Financial Transaction Manager 3.2.4 does not invalidate session any existing session identifier gives an attacker the opportunity to steal authen…EPSS 0.64%8.8CVE-2018-1790Ibm financial transaction manager cross-site request forgery vulnerabilityIBM Financial Transaction Manager for Digital Payments for Multi-Platform 3.0.2 is vulnerable to cross-site request forgery which could allow an atta…EPSS 0.53%8.8CVE-2018-1819Ibm financial transaction manager sql injection vulnerabilityIBM Financial Transaction Manager for Digital Payments for Multi-Platform 3.0.2, 3.0.4, 3.0.6, and 3.2.0 is vulnerable to SQL injection. A remote att…EPSS 1.7%

Source: NIST National Vulnerability Database (record CVE-2020-5003), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.