Junglewise Threat Intelligence

CVE-2025-36148: IBM Financial Transaction Manager SWIFT cross-site scripting in Web UI

CVE-2025-36148 · Severity: medium · CVSS 5.4 · Published 2026-05-26

Vendors: IBM.

Executive brief

IBM Financial Transaction Manager for SWIFT Services, a platform used by financial institutions to manage high-value payment messaging, is affected by a security vulnerability in its web interface. An attacker could use this flaw to execute malicious scripts in a user's browser, potentially leading to the theft of login credentials or unauthorized actions within the application. Organizations should update to Fix Pack 16 to protect their transaction management environment.

Technical details

A stored or reflected cross-site scripting (XSS) vulnerability exists in the Web UI of IBM Financial Transaction Manager for SWIFT Services for Multiplatforms versions 3.2.4.0 through 3.2.4.15. The flaw stems from improper neutralization of user-supplied input during web page generation (CWE-79). An attacker can exploit this by injecting malicious JavaScript into the interface, which then executes in the context of a victim's browser session. Successful exploitation requires some user interaction and can lead to the disclosure of sensitive session information or credentials. The issue is resolved in Fix Pack 16.

Affected products

  • IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4.0 through 3.2.4.15

Timeline

  • 2026-05-07: disclosed: Initial publication by IBM
  • 2026-05-07: patched: Fix Pack 16 released
  • 2026-05-26: advisory: NVD publication date

References

Related threats