Cross-Site Scripting Vulnerability in IBM Financial Transaction Manager
CVE-2025-36147

6.1MEDIUM

What is CVE-2025-36147?

The IBM Financial Transaction Manager for SWIFT Services for Multiplatforms, versions 3.2.4.0 to 3.2.4.16, is susceptible to cross-site scripting (XSS). This vulnerability enables unauthenticated attackers to inject arbitrary JavaScript code into the web interface. Such code execution can compromise user sessions by revealing sensitive information, including credentials. Organizations are advised to review the affected versions and apply the necessary patches to mitigate potential exploitation.

Affected Version(s)

Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4.0 <= 3.2.4.16

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.