First published: Fri Dec 22 2023(Updated: )
In the Message Entry and Repair (MER) facility of Financial Transaction Manager for SWIFT Services the sending address and the message type of FIN messages are assumed to be immutable. However, an attacker might modify these elements of a business transaction.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Financial Transaction Manager SWIFT services | <=3.2.4 | |
IBM Financial Transaction Manager | =3.2.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-49880 is considered a critical vulnerability due to its potential impact on financial transactions.
To fix CVE-2023-49880, ensure that you update IBM Financial Transaction Manager for SWIFT Services to version 3.2.4 or later.
The implications of CVE-2023-49880 include the potential for attackers to alter key elements of business transactions, jeopardizing transactional integrity.
CVE-2023-49880 affects IBM Financial Transaction Manager for SWIFT Services version 3.2.4 and prior versions.
Organizations using IBM Financial Transaction Manager for SWIFT Services for managing financial transactions are affected by CVE-2023-49880.