VulnerabilityModified
CVE-2023-49880
However, an attacker might modify these elements of a business transaction.
HIGH 7.5EPSS 0.54%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.54%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
In the Message Entry and Repair (MER) facility of IBM Financial Transaction Manager for SWIFT Services 3.2.4 the sending address and the message type of FIN messages are assumed to be immutable. However, an attacker might modify these elements of a business transaction. IBM X-Force ID: 273183.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 0.54% probability · 44th percentile
- CISA KEV
- Not listed
- Affected
- ibm/financial transaction manager
- Source
- psirt@us.ibm.com
References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/273183VDB Entry, Vendor Advisory
- https://www.ibm.com/support/pages/node/7101167Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/273183VDB Entry, Vendor Advisory
- https://www.ibm.com/support/pages/node/7101167Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.