Junglewise Threat Intelligence

CVE-2026-17620: IBM Financial Transaction Manager cleartext transmission of sensitive data

CVE-2026-17620 · Severity: medium · CVSS 5.3 · Published 2026-09-22

Technologies: IBM Financial Transaction Manager. Vendors: IBM.

Executive brief

IBM Financial Transaction Manager, a financial processing platform used for payment transactions and business operations, transmits sensitive or security-critical data in unencrypted cleartext over the network. This allows attackers with network access to intercept and read confidential information such as credentials or transaction details. The vulnerability affects multiple versions of the product deployed on RedHat OpenShift.

Technical details

The vulnerability involves improper handling of sensitive data in network communications, allowing attackers to sniff cleartext traffic containing security-critical information. This is a classic insecure transmission vulnerability affecting the core communication channels used by FTM. Exploitation requires only network access and does not require authentication or user interaction, though the attacker must be positioned on the network path.

Affected products

  • IBM Financial Transaction Manager 4.0.6.0 through 4.0.10.0, including Operator 4.4.6+20260807.081800

Timeline

  • 2026-09-22: disclosed

References

Related threats