Executive brief
IBM Financial Transaction Manager (FTM), a financial transaction processing system running on Red Hat OpenShift, allows authenticated remote attackers to gain elevated privileges through improper privilege management controls. Successful exploitation could enable unauthorized users to perform administrative actions, modify system configurations, and access or alter sensitive financial transaction data.
Technical details
A privilege management flaw in FTM allows authenticated remote attackers to escalate their privileges without additional authentication or interaction. The vulnerability stems from insufficient authorization checks that fail to properly restrict access to critical functions based on user roles. Exploitation results in complete system compromise with ability to execute privileged operations.
Affected products
- IBM Financial Transaction Manager <UNKNOWN>
Timeline
- 2026-09-22: disclosed