Executive brief
IBM Financial Transaction Manager (FTM) is a financial transaction processing platform deployed on RedHat OpenShift. Improper configuration of HTTP method-based security constraints allows remote attackers to bypass access controls and perform unauthorized financial or administrative actions without proper authentication. This could lead to fraudulent transactions, data theft, or system compromise.
Technical details
The vulnerability stems from inadequate enforcement of HTTP method-based security constraints, allowing unauthenticated or low-privileged remote attackers to invoke protected operations via HTTP requests. The flaw permits direct access to sensitive endpoints that should require authentication or higher privilege levels. A patch is available from IBM.
Affected products
- IBM Financial Transaction Manager
Timeline
- 2026-09-22: disclosed