CVE Vulnerabilities

CVE-2023-49880

Published: Dec 25, 2023 | Modified: Jan 03, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

In the Message Entry and Repair (MER) facility of IBM Financial Transaction Manager for SWIFT Services 3.2.4 the sending address and the message type of FIN messages are assumed to be immutable. However, an attacker might modify these elements of a business transaction. IBM X-Force ID: 273183.

Affected Software

Name Vendor Start Version End Version
Financial_transaction_manager Ibm 3.2.4 (including) 3.2.4 (including)

References