PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-36148 IBM CVE debrief

IBM Financial Transaction Manager for SWIFT Services for Multiplatforms versions 3.2.4.0 through 3.2.4.15 contains a cross-site scripting (XSS) vulnerability. An unauthenticated attacker can inject arbitrary JavaScript code into the Web UI, potentially leading to credential disclosure within a trusted session. The vulnerability was published to the NVD on 2026-05-26 and remains in 'Awaiting Analysis' status. IBM has published a security bulletin with remediation guidance.

Vendor
IBM
Product
Financial Transaction Manager for SWIFT Services for Multiplatforms
CVSS
MEDIUM 5.4
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-26
Original CVE updated
2026-06-01
Advisory published
2026-05-26
Advisory updated
2026-06-01

Who should care

Organizations operating IBM Financial Transaction Manager for SWIFT Services for Multiplatforms versions 3.2.4.0 through 3.2.4.15, particularly financial institutions processing SWIFT transactions. Security teams responsible for web application security, fraud prevention, and SWIFT infrastructure protection.

Technical summary

The vulnerability exists in IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4.0-3.2.4.15 due to improper neutralization of user input in the Web UI (CWE-79). The attack vector is network-based with low attack complexity, requiring low privileges and user interaction. The scope is changed (S:C) with low impacts to confidentiality and integrity. No availability impact. Attackers can embed arbitrary JavaScript to alter functionality and harvest credentials from authenticated sessions.

Defensive priority

medium

Recommended defensive actions

  • Apply IBM security updates per IBM security bulletin when available
  • Review and implement input validation and output encoding controls for Web UI components
  • Monitor for unauthorized access attempts to Financial Transaction Manager Web interfaces
  • Validate Content Security Policy (CSP) headers are configured to mitigate XSS impact
  • Conduct security review of session management mechanisms to limit credential exposure scope

Evidence notes

CVE published 2026-05-26T17:16:29.013Z; modified 2026-05-26T19:06:14.330Z. IBM PSIRT reference confirms vendor acknowledgment. CVSS 3.1 vector: AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N. CWE-79 (Improper Neutralization of Input During Web Page Generation) identified as primary weakness.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-36148 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-36148

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-36148 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-36148

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.