Executive brief
IBM Financial Transaction Manager (FTM) is a payment processing and financial transaction platform for OpenShift. A local attacker can exploit a server-side request forgery vulnerability to obtain sensitive information and trigger unauthorized financial actions, potentially compromising payment processing integrity and confidentiality.
Technical details
A server-side request forgery (SSRF) vulnerability in IBM FTM allows a local attacker to make the server issue requests on their behalf, enabling information disclosure and unauthorized action execution. The vulnerability requires local access and does not mandate prior authentication. A patch is expected to be available from IBM.
Affected products
- IBM Financial Transaction Manager <UNKNOWN>
Timeline
- 2026-09-22: disclosed