Executive brief
IBM Financial Transaction Manager (FTM) is middleware that processes financial transactions and business operations. A local attacker with limited privileges can read insufficiently protected credentials from the system, potentially gaining unauthorized access to sensitive financial data or elevated system capabilities. This could lead to fraudulent transactions, data theft, or further system compromise.
Technical details
CWE-522: Insufficiently Protected Credentials. The vulnerability allows a local attacker with low privileges to access plaintext or weakly protected credentials stored on the system. Attack requires local system access but no elevated privileges. An attacker gains the ability to read credentials that provide high-confidentiality access across the system scope.
Affected products
- IBM Financial Transaction Manager
Timeline
- 2026-09-22: disclosed