IBM Financial Transaction Manager 3.0.6 and 3.1.0 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 183328.
| Software | From | Fixed in |
|---|---|---|
| ibm / financial_transaction_manager | 2.1.1.0 | 2.1.1.0.x |
| ibm / financial_transaction_manager | 3.2.1 | 3.2.1.x |
| ibm / financial_transaction_manager | 3.0.2 | 3.0.2.x |
| ibm / financial_transaction_manager | 3.2.4 | 3.2.4.x |
| ibm / financial_transaction_manager | 3.2.2 | 3.2.2.x |
| ibm / financial_transaction_manager | 3.2.3 | 3.2.3.x |
| ibm / financial_transaction_manager | 3.0.0 | 3.0.0.x |
| ibm / financial_transaction_manager | 3.0.5 | 3.0.5.x |
| ibm / financial_transaction_manager | 3.0.6 | 3.0.6.x |
| ibm / financial_transaction_manager | 3.1.0 | 3.1.0.x |