First published: Fri Mar 31 2023(Updated: )
IBM Financial Transaction Manager for SWIFT Services 3.2.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 239707.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ibm Financial Transaction Manager For Multiplatform | =3.2.4 | |
IBM Financial Transaction Manager for SWIFT Services for Multiplatforms | <=3.2.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-43871.
The severity of CVE-2022-43871 is medium with a CVSS score of 5.4.
The cross-site scripting vulnerability in CVE-2022-43871 allows users to inject arbitrary JavaScript code in the Web UI of IBM Financial Transaction Manager, potentially leading to credentials disclosure within a trusted session.
IBM Financial Transaction Manager for SWIFT Services 3.2.4 is affected by CVE-2022-43871.
To fix the vulnerability, apply the necessary security updates provided by IBM.