← Vulnerability feed

Vulnerability record · CVE-2021-39044 · published 2 February 2022

CVE-2021-39044: Ibm financial transaction manager cross-site request forgery vulnerability

Ibm · Financial Transaction Manager

IBM Financial Transaction Manager 3.2.4 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 214210.

8.8 CVSS 3.1 High EPSS 0.38% · top 70.1% CWE-352 · Cross-site request forgery
8.8CVSS 3.1 base score, v2 6.8
0.38%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

IBM Financial Transaction Manager 3.2.4 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 214210.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-39044 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-4575Ibm financial transaction manager sql injection vulnerabilityIBM Financial Transaction Manager for Digital Payments for Multi-Platform 3.2.0 through 3.2.9 is vulnerable to SQL injection. A remote attacker could…EPSS 1.1%9.8CVE-2019-4032Ibm financial transaction manager sql injection vulnerabilityIBM Financial Transaction Manager for Digital Payments for Multi-Platform 3.1.0 is vulnerable to SQL injection. A remote attacker could send speciall…EPSS 1.6%9.1CVE-2023-35892Ibm financial transaction manager xml external entity (xxe) vulnerabilityIBM Financial Transaction Manager for SWIFT Services 3.2.4 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A…EPSS 1.1%9.1CVE-2020-5003Ibm financial transaction manager xml external entity (xxe) vulnerabilityIBM Financial Transaction Manager 3.2.4 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker co…EPSS 1.8%8.8CVE-2020-5002Ibm financial transaction manager improper input validation vulnerabilityIBM Financial Transaction Manager 3.2.0 through 3.2.10 could allow an authenticated user to perform unauthorized actions due to improper validation. …EPSS 0.58%8.8CVE-2021-39066Ibm financial transaction manager vulnerabilityIBM Financial Transaction Manager 3.2.4 does not invalidate session any existing session identifier gives an attacker the opportunity to steal authen…EPSS 0.64%8.8CVE-2018-1790Ibm financial transaction manager cross-site request forgery vulnerabilityIBM Financial Transaction Manager for Digital Payments for Multi-Platform 3.0.2 is vulnerable to cross-site request forgery which could allow an atta…EPSS 0.53%8.8CVE-2018-1819Ibm financial transaction manager sql injection vulnerabilityIBM Financial Transaction Manager for Digital Payments for Multi-Platform 3.0.2, 3.0.4, 3.0.6, and 3.2.0 is vulnerable to SQL injection. A remote att…EPSS 1.7%

Source: NIST National Vulnerability Database (record CVE-2021-39044), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.