Executive brief
IBM Financial Transaction Manager (FTM), a financial transaction processing application, contains a path traversal vulnerability that allows authenticated users to modify files on the server. An attacker with valid credentials could alter critical business files, potentially affecting transaction processing and system integrity.
Technical details
A path traversal vulnerability (CWE-22) in IBM FTM allows remote authenticated attackers to bypass pathname restrictions and modify arbitrary server files through improperly validated input. The attack requires valid authentication credentials and network access but no user interaction. Successful exploitation results in integrity compromise of server files.
Affected products
- IBM Financial Transaction Manager
Timeline
- 2026-09-22: disclosed