First published: Fri Sep 01 2023(Updated: )
IBM Financial Transaction Manager for SWIFT Services 3.2.4 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 258786.
Credit: psirt@us.ibm.com psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Financial Transaction Manager for SWIFT Services for Multiplatforms | =3.2.4 | |
IBM Financial Transaction Manager for SWIFT Services for Multiplatforms | <=3.2.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-35892.
The severity of CVE-2023-35892 is critical.
CVE-2023-35892 allows an attacker to perform an XML External Entity Injection (XXE) attack, potentially exposing sensitive information or consuming memory resources.
IBM Financial Transaction Manager for SWIFT Services version 3.2.4 is affected by CVE-2023-35892.
To fix CVE-2023-35892, apply the necessary security patches or updates provided by IBM.