CVE-2023-49880: IBM Financial Transaction Manager for SWIFT Services data manipulation
In the Message Entry and Repair (MER) facility of Financial Transaction Manager for SWIFT Services the sending address and the message type of FIN messages are assumed to be immutable. However, an attacker might modify these elements of a business transaction.
Other sources
In the Message Entry and Repair (MER) facility of IBM Financial Transaction Manager for SWIFT Services 3.2.4 the sending address and the message type of FIN messages are assumed to be immutable. However, an attacker might modify these elements of a business transaction. IBM X-Force ID: 273183.
— NVD
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-49880?
CVE-2023-49880 is considered a critical vulnerability due to its potential impact on financial transactions.
How do I fix CVE-2023-49880?
To fix CVE-2023-49880, ensure that you update IBM Financial Transaction Manager for SWIFT Services to version 3.2.4 or later.
What are the implications of CVE-2023-49880?
The implications of CVE-2023-49880 include the potential for attackers to alter key elements of business transactions, jeopardizing transactional integrity.
Which software versions are affected by CVE-2023-49880?
CVE-2023-49880 affects IBM Financial Transaction Manager for SWIFT Services version 3.2.4 and prior versions.
Who is affected by CVE-2023-49880?
Organizations using IBM Financial Transaction Manager for SWIFT Services for managing financial transactions are affected by CVE-2023-49880.