CVE-2023-49880

HIGH

IBM Financial Transaction Manager for SWIFT Services <3.2.4 - Info ...

Title source: llm
STIX 2.1

Description

In the Message Entry and Repair (MER) facility of IBM Financial Transaction Manager for SWIFT Services 3.2.4 the sending address and the message type of FIN messages are assumed to be immutable. However, an attacker might modify these elements of a business transaction. IBM X-Force ID: 273183.

References (2)

Core 2
Core References
Vendor Advisory vendor-advisory
https://www.ibm.com/support/pages/node/7101167

Scores

CVSS v3 7.5
EPSS 0.0005
EPSS Percentile 14.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

Status published
Products (1)
ibm/financial_transaction_manager 3.2.4
Published Dec 25, 2023
Tracked Since Feb 18, 2026