CVE-2024-49349

IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4.0 through 3.2.4.1 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
References
Link Resource
https://www.ibm.com/support/pages/node/7182203 Vendor Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:ibm:financial_transaction_manager_for_multiplatform:*:*:*:*:*:swift_services:*:*
OR cpe:2.3:o:ibm:aix:-:*:*:*:*:*:*:*
cpe:2.3:o:ibm:linux_on_ibm_z:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*

History

13 Aug 2025, 17:34

Type Values Removed Values Added
Summary
  • (es) IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4.0 a 3.2.4.1 es vulnerable a Cross-Site Scripting Almacenado. Esta vulnerabilidad permite a los usuarios autenticados incorporar código JavaScript arbitrario en la interfaz de usuario web, alterando así la funcionalidad prevista y pudiendo provocar la divulgación de credenciales dentro de una sesión de confianza.
First Time Ibm financial Transaction Manager For Multiplatform
Linux linux Kernel
Ibm aix
Ibm
Linux
Ibm linux On Ibm Z
References () https://www.ibm.com/support/pages/node/7182203 - () https://www.ibm.com/support/pages/node/7182203 - Vendor Advisory
CPE cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:a:ibm:financial_transaction_manager_for_multiplatform:*:*:*:*:*:swift_services:*:*
cpe:2.3:o:ibm:aix:-:*:*:*:*:*:*:*
cpe:2.3:o:ibm:linux_on_ibm_z:-:*:*:*:*:*:*:*

31 Jan 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-31 17:15

Updated : 2025-08-13 17:34


NVD link : CVE-2024-49349

Mitre link : CVE-2024-49349

CVE.ORG link : CVE-2024-49349


JSON object : View

Products Affected

ibm

  • financial_transaction_manager_for_multiplatform
  • linux_on_ibm_z
  • aix

linux

  • linux_kernel
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')