Executive brief
IBM Financial Transaction Manager (FTM) is a payment processing platform used for secure financial transactions on OpenShift. A vulnerability in the web interface allows an attacker to inject malicious JavaScript that executes in the browser of any authenticated user, potentially enabling account takeover, credential theft, or fraudulent transactions through actions performed on the victim's behalf.
Technical details
The vulnerability is a cross-site scripting (XSS) flaw caused by improper neutralization of HTML input in the web interface. An unauthenticated attacker can craft a malicious request that causes JavaScript to execute in the context of an authenticated user's session, achieving persistence across the application scope. The attack requires user interaction (clicking a link) but no prior authentication on the attacker's part.
Affected products
- IBM Financial Transaction Manager 4.x and earlier
Timeline
- 2026-09-22: disclosed