Executive brief
IBM Financial Transaction Manager (FTM) is middleware software that processes financial transactions in enterprise environments. A flaw in how the system validates file paths allows remote attackers to read arbitrary files from the server, potentially exposing sensitive financial data, credentials, and system configuration. This could lead to unauthorized access to payment information and compromise of the underlying infrastructure.
Technical details
The vulnerability stems from improper path canonicalization that fails to restrict file access to intended directories, allowing directory traversal attacks. A remote attacker can craft requests with manipulated path parameters to bypass access controls and read files outside the intended scope. No authentication is required to exploit this flaw, making it remotely accessible from the network.
Affected products
- IBM Financial Transaction Manager 4.x and earlier
Timeline
- 2026-09-22: disclosed