PatchSiren cyber security CVE debrief
CVE-2025-36148 IBM CVE debrief
IBM Financial Transaction Manager for SWIFT Services for Multiplatforms versions 3.2.4.0 through 3.2.4.15 contains a cross-site scripting (XSS) vulnerability. An unauthenticated attacker can inject arbitrary JavaScript code into the Web UI, potentially leading to credential disclosure within a trusted session. The vulnerability was published to the NVD on 2026-05-26 and remains in 'Awaiting Analysis' status. IBM has published a security bulletin with remediation guidance.
- Vendor
- IBM
- Product
- Financial Transaction Manager for SWIFT Services for Multiplatforms
- CVSS
- MEDIUM 5.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-26
- Original CVE updated
- 2026-06-01
- Advisory published
- 2026-05-26
- Advisory updated
- 2026-06-01
Who should care
Organizations operating IBM Financial Transaction Manager for SWIFT Services for Multiplatforms versions 3.2.4.0 through 3.2.4.15, particularly financial institutions processing SWIFT transactions. Security teams responsible for web application security, fraud prevention, and SWIFT infrastructure protection.
Technical summary
The vulnerability exists in IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4.0-3.2.4.15 due to improper neutralization of user input in the Web UI (CWE-79). The attack vector is network-based with low attack complexity, requiring low privileges and user interaction. The scope is changed (S:C) with low impacts to confidentiality and integrity. No availability impact. Attackers can embed arbitrary JavaScript to alter functionality and harvest credentials from authenticated sessions.
Defensive priority
medium
Recommended defensive actions
- Apply IBM security updates per IBM security bulletin when available
- Review and implement input validation and output encoding controls for Web UI components
- Monitor for unauthorized access attempts to Financial Transaction Manager Web interfaces
- Validate Content Security Policy (CSP) headers are configured to mitigate XSS impact
- Conduct security review of session management mechanisms to limit credential exposure scope
Evidence notes
CVE published 2026-05-26T17:16:29.013Z; modified 2026-05-26T19:06:14.330Z. IBM PSIRT reference confirms vendor acknowledgment. CVSS 3.1 vector: AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N. CWE-79 (Improper Neutralization of Input During Web Page Generation) identified as primary weakness.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-36148 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-36148
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-36148 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-36148
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://www.ibm.com/support/pages/node/7272275
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.