Impact
The vulnerability is a cross‑site scripting flaw that allows an unauthenticated attacker to embed arbitrary JavaScript into the IBM Financial Transaction Manager web interface. This enables the attacker to modify the user interface, hijack session cookies, or otherwise exfiltrate credentials, compromising the confidentiality and integrity of the system’s authentication data. The weakness corresponds to CWE‑79, which denotes improper neutralization of input during web page generation.
Affected Systems
IBM Financial Transaction Manager for SWIFT Services for Multiplatforms from version 3.2.4.0 through 3.2.4.16 is affected.
Risk and Exploitability
The flaw carries a CVSS score of 6.1 and is considered a moderate risk. The EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog. Because the attack requires no authentication and can be performed through the exposed Web UI, the attack vector is remote and low effort. An attacker can readily inject malicious payloads into the UI, potentially compromising user sessions without needing privileged access.
OpenCVE Enrichment