Executive brief
IBM Financial Transaction Manager (FTM), a core banking platform for processing financial transactions, contains a vulnerability that allows remote attackers to crash the system via unsafe reflection. An attacker exploiting this issue can cause service outages that disrupt payment processing and transaction operations.
Technical details
The vulnerability exists in unsafe reflection logic that accepts externally controlled input without proper validation, allowing an attacker to instantiate or invoke arbitrary classes (CWE-470). A remote attacker can send a specially crafted request over an adjacent network to trigger the reflection vulnerability and cause denial of service. The attack requires no authentication or user interaction.
Affected products
- IBM Financial Transaction Manager
Timeline
- 2026-09-22: disclosed