CVE-2023-49880

3 documents3 sources
Severity
7.5HIGH
EPSS
0.0%
top 85.73%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 25

Description

In the Message Entry and Repair (MER) facility of IBM Financial Transaction Manager for SWIFT Services 3.2.4 the sending address and the message type of FIN messages are assumed to be immutable. However, an attacker might modify these elements of a business transaction. IBM X-Force ID: 273183.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

🔴Vulnerability Details

2
CVEList
IBM Financial Transaction Manager for SWIFT Services data manipulation2023-12-25
GHSA
GHSA-9mr3-mrj5-pc9x: In the Message Entry and Repair (MER) facility of IBM Financial Transaction Manager for SWIFT Services 32023-12-25
CVE-2023-49880 (HIGH CVSS 7.5) | In the Message Entry and Repair (ME | cvebase.io