IBM Security Update – 25 December 2023

IBM has released a security update to fix a vulnerability in IBM Financial Transaction Manager for SWIFT Services version 3.2.4.

The addressed vulnerability could allow the remote attacker to modify the sending address and the message type of a business transaction. However, these elements of FIN messages are assumed to be immutable in the Message Entry and Repair
(MER) facility of the affected system.

IBM Financial Transaction Manager for SWIFT Services Data Manipulation Vulnerability (CVE-2023-49880):

  • CVSS:7.5
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Data Manipulation
Vulnerabilities

CVE-2023-49880

Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

IBM Financial Transaction Manager for SWIFT Services Security Bulletin

References