Executive brief
IBM Financial Transaction Manager for SWIFT Services is a critical enterprise application used to manage international financial transactions via the SWIFT network. An unauthenticated attacker can inject malicious JavaScript code into the Web UI, allowing them to alter functionality and potentially steal user credentials during active sessions. This vulnerability creates a risk of fraud, data theft, and operational disruption in banking environments.
Technical details
This is a stored or reflected cross-site scripting (XSS) vulnerability (CWE-79) in the Web UI of IBM Financial Transaction Manager for SWIFT Services. The vulnerability exists because the application lacks proper input sanitization and content security policy (CSP) directives, relying on a broad fallback policy instead. An unauthenticated attacker can embed arbitrary JavaScript in the UI with no authentication required; user interaction (clicking a malicious link) is needed to trigger the exploit. A successful attack allows the attacker to alter functionality, steal session credentials, or perform actions on behalf of the victim. IBM released Fix Pack 17 to address this issue; customers should upgrade from versions 3.2.4.0 through 3.2.4.16.
Affected products
- IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4.0 through 3.2.4.16
Timeline
- 2026-09-01: disclosed: IBM security bulletin published
- 2026-09-18: advisory: NVD record created