CVE-2023-49880: IBM Financial Transaction Manager

High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.

In the Message Entry and Repair (MER) facility of IBM Financial Transaction Manager for SWIFT Services 3.2.4 the sending address and the message type of FIN messages are assumed to be immutable. However, an attacker might modify these elements of a business transaction. IBM X-Force ID: 273183.

Affected products

  • IBM Financial Transaction Manager: version 3.2.4 only

Published 2023-12-25. Last modified 2026-06-17.