Executive brief
IBM Financial Transaction Manager (FTM) is a payment processing system used to manage financial transactions in enterprise environments. An authenticated attacker can exploit improper handling of XML input to access sensitive information like credentials, account details, or system configuration data. This could lead to further compromise of the financial transaction system and exposure of customer data.
Technical details
The vulnerability stems from improper restriction of XML external entity (XXE) references in FTM's XML parsing logic, allowing an authenticated network-based attacker to read arbitrary files or access internal system resources. The attacker must have valid authentication credentials but can then retrieve sensitive information without further authorization. The issue affects FTM's core XML processing without requiring user interaction.
Affected products
- IBM Financial Transaction Manager
Timeline
- 2026-09-22: disclosed