CVE-2023-35892: IBM Financial Transaction Manager for SWIFT Services XML external entity injection
IBM Financial Transaction Manager for SWIFT Services 3.2.4 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 258786.
Other sources
IBM Financial Transaction Manager for SWIFT Services is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2023-35892.
What is the severity of CVE-2023-35892?
The severity of CVE-2023-35892 is critical.
How does CVE-2023-35892 impact IBM Financial Transaction Manager for SWIFT Services?
CVE-2023-35892 allows an attacker to perform an XML External Entity Injection (XXE) attack, potentially exposing sensitive information or consuming memory resources.
Which version of IBM Financial Transaction Manager for SWIFT Services is affected by CVE-2023-35892?
IBM Financial Transaction Manager for SWIFT Services version 3.2.4 is affected by CVE-2023-35892.
How can I fix CVE-2023-35892 in IBM Financial Transaction Manager for SWIFT Services?
To fix CVE-2023-35892, apply the necessary security patches or updates provided by IBM.