Executive brief
IBM Financial Transaction Manager (FTM) is software used to manage and process financial transactions for enterprises. An adjacent network attacker could exploit unsafe deserialization of untrusted data to execute arbitrary code on affected systems, potentially compromising transaction processing, stealing financial data, or disrupting payment operations.
Technical details
The vulnerability stems from unsafe deserialization of untrusted data in IBM FTM, allowing remote code execution when an attacker on the adjacent network sends crafted serialized objects. This requires network access to the affected component but does not require authentication or user interaction. Successful exploitation grants the attacker arbitrary code execution on the server with the privileges of the FTM application.
Affected products
- IBM Financial Transaction Manager (FTM)
Timeline
- 2026-09-22: disclosed