Vulnerability Description
In the Message Entry and Repair (MER) facility of IBM Financial Transaction Manager for SWIFT Services 3.2.4 the sending address and the message type of FIN messages are assumed to be immutable. However, an attacker might modify these elements of a business transaction. IBM X-Force ID: 273183.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Financial Transaction Manager | 3.2.4 |
References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/273183VDB EntryVendor Advisory
- https://www.ibm.com/support/pages/node/7101167Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/273183VDB EntryVendor Advisory
- https://www.ibm.com/support/pages/node/7101167Vendor Advisory
FAQ
What is CVE-2023-49880?
CVE-2023-49880 is a vulnerability with a CVSS score of 7.5 (HIGH). In the Message Entry and Repair (MER) facility of IBM Financial Transaction Manager for SWIFT Services 3.2.4 the sending address and the message type of FIN messages are assumed to be immutable. Howev...
How severe is CVE-2023-49880?
CVE-2023-49880 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-49880?
Check the references section above for vendor advisories and patch information. Affected products include: Ibm Financial Transaction Manager.