Executive brief
IBM Financial Transaction Manager (FTM), a payment processing system for OpenShift, allows local attackers to execute arbitrary commands by exploiting functionality from an untrusted source. This could enable attackers with local access to the system to take complete control, compromise payment transactions, or steal financial data.
Technical details
A local attacker can execute arbitrary commands on the FTM system due to inclusion of untrusted functionality in the control sphere. The vulnerability requires local access to the system and allows complete command execution. No patch status is indicated in the advisory.
Affected products
- IBM Financial Transaction Manager
Timeline
- 2026-09-22: disclosed