Executive brief
IBM Financial Transaction Manager is a financial platform that processes and manages payment transactions for enterprises. A missing authorization flaw allows authenticated attackers to perform unauthorized changes to payment transactions, potentially resulting in fraudulent payment mutations or financial loss. The vulnerability requires attacker authentication but bypasses controls on sensitive payment operations.
Technical details
The vulnerability is caused by missing authorization checks in payment mutation endpoints. An authenticated remote attacker can invoke payment modification functions without proper permission validation, allowing them to alter transaction details. The attack vector is network-based and requires prior authentication but no user interaction.
Affected products
- IBM Financial Transaction Manager
Timeline
- 2026-09-22: disclosed