Cross-Site Scripting Vulnerability in IBM Financial Transaction Manager for SWIFT Services
CVE-2025-36148

5.4MEDIUM

What is CVE-2025-36148?

IBM Financial Transaction Manager for SWIFT Services versions 3.2.4.0 through 3.2.4.15 are susceptible to a cross-site scripting vulnerability. This flaw allows attackers without authentication to inject malicious JavaScript into the Web User Interface. This manipulation can compromise user sessions, enabling the potential disclosure of sensitive credentials. Users are advised to apply the latest patches to mitigate this vulnerability, ensuring the integrity and security of their financial transactions.

Affected Version(s)

Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4.0 <= 3.2.4.15

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.