Description
IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4.0 through 3.2.4.16 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Published: 2026-09-18
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Client-side code injection that can lead to credential disclosure
Action: Patch Immediately
AI Analysis

Impact

The vulnerability is a cross‑site scripting flaw that allows an unauthenticated attacker to embed arbitrary JavaScript into the IBM Financial Transaction Manager web interface. This enables the attacker to modify the user interface, hijack session cookies, or otherwise exfiltrate credentials, compromising the confidentiality and integrity of the system’s authentication data. The weakness corresponds to CWE‑79, which denotes improper neutralization of input during web page generation.

Affected Systems

IBM Financial Transaction Manager for SWIFT Services for Multiplatforms from version 3.2.4.0 through 3.2.4.16 is affected.

Risk and Exploitability

The flaw carries a CVSS score of 6.1 and is considered a moderate risk. The EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog. Because the attack requires no authentication and can be performed through the exposed Web UI, the attack vector is remote and low effort. An attacker can readily inject malicious payloads into the UI, potentially compromising user sessions without needing privileged access.

Generated by OpenCVE AI on September 19, 2026 at 17:23 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now by upgrading to Fix Pack 17. Product(s)Version(s)Remediation/Fix/InstructionsIBM Financial Transaction Manager for SWIFT Services for Multiplatforms3.2.4.0-3.2.4.16Install Fix Pack 17 of IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4 https://www.ibm.com/support/fixcentral/swg/selectFixes


OpenCVE Recommended Actions

  • Upgrade the product to IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4 Fix Pack 17 via IBM Fix Central and ensure the installer is applied to all affected instances.
  • Implement proper output encoding or input validation on all user‑controlled content in the Web UI to mitigate the cross‑site scripting risk until a patch is deployed.
  • Restrict external access to the Web UI, enforce strict user authentication, and monitor application logs for suspicious JavaScript payloads or anomalous session activity.

Generated by OpenCVE AI on September 19, 2026 at 17:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Description IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4.0 through 3.2.4.16 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Title IBM Financial Transaction Manager for SWIFT Services for Multiplatforms is vulnerable to cross-site scripting.
First Time appeared Ibm
Ibm financial Transaction Manager For Swift Services For Multiplatforms
Weaknesses CWE-79
CPEs cpe:2.3:a:ibm:financial_transaction_manager_for_swift_services_for_multiplatforms:3.2.4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:financial_transaction_manager_for_swift_services_for_multiplatforms:3.2.4.16:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm financial Transaction Manager For Swift Services For Multiplatforms
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Ibm Financial Transaction Manager For Swift Services For Multiplatforms
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-22T16:07:52.514Z

Reserved: 2025-04-15T21:16:19.940Z

Link: CVE-2025-36147

cve-icon Vulnrichment

Updated: 2026-09-22T16:06:18.827Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T16:17:03.060

Modified: 2026-09-22T17:17:22.330

Link: CVE-2025-36147

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T17:30:07Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')