IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4.0 through 3.2.4.16 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
IBM strongly recommends addressing the vulnerability now by upgrading to Fix Pack 17.
Product(s)Version(s)Remediation/Fix/InstructionsIBM Financial Transaction Manager for SWIFT Services for Multiplatforms3.2.4.0-3.2.4.16Install Fix Pack 17 of IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4 https://www.ibm.com/support/fixcentral/swg/selectFixes