Multiple cross-site scripting (XSS) vulnerabilities in configuration-details screens in the OAC component in IBM Financial Transaction Manager (FTM) 2.0 before 2.0.0.3 allow remote authenticated users to inject arbitrary web script or HTML via a crafted text value.
| Software | From | Fixed in |
|---|---|---|
| ibm / financial_transaction_manager | 2.0.0.2 | 2.0.0.2.x |
| ibm / financial_transaction_manager | 2.0.0.0 | 2.0.0.0.x |
| ibm / financial_transaction_manager | 2.0.0.1 | 2.0.0.1.x |