PatchSiren cyber security CVE debrief
CVE-2025-36148 IBM CVE debrief
IBM Financial Transaction Manager for SWIFT Services for Multiplatforms versions 3.2.4.0 through 3.2.4.15 contains a cross-site scripting (XSS) vulnerability. An unauthenticated attacker can inject arbitrary JavaScript code into the Web UI, potentially leading to credential disclosure within a trusted session. The vulnerability was published to the NVD on 2026-05-26 and remains in 'Awaiting Analysis' status. IBM has published a security bulletin with remediation guidance.
- Vendor
- IBM
- Product
- Financial Transaction Manager for SWIFT Services for Multiplatforms
- CVSS
- MEDIUM 5.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-26
- Original CVE updated
- 2026-05-26
- Advisory published
- 2026-05-26
- Advisory updated
- 2026-05-26
Who should care
Organizations operating IBM Financial Transaction Manager for SWIFT Services for Multiplatforms versions 3.2.4.0 through 3.2.4.15, particularly financial institutions processing SWIFT transactions. Security teams responsible for web application security, fraud prevention, and SWIFT infrastructure protection.
Technical summary
The vulnerability exists in IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4.0-3.2.4.15 due to improper neutralization of user input in the Web UI (CWE-79). The attack vector is network-based with low attack complexity, requiring low privileges and user interaction. The scope is changed (S:C) with low impacts to confidentiality and integrity. No availability impact. Attackers can embed arbitrary JavaScript to alter functionality and harvest credentials from authenticated sessions.
Defensive priority
medium
Recommended defensive actions
- Apply IBM security updates per IBM security bulletin when available
- Review and implement input validation and output encoding controls for Web UI components
- Monitor for unauthorized access attempts to Financial Transaction Manager Web interfaces
- Validate Content Security Policy (CSP) headers are configured to mitigate XSS impact
- Conduct security review of session management mechanisms to limit credential exposure scope
Evidence notes
CVE published 2026-05-26T17:16:29.013Z; modified 2026-05-26T19:06:14.330Z. IBM PSIRT reference confirms vendor acknowledgment. CVSS 3.1 vector: AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N. CWE-79 (Improper Neutralization of Input During Web Page Generation) identified as primary weakness.
Official resources
-
CVE-2025-36148 CVE record
CVE.org
-
CVE-2025-36148 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
public