Executive brief
IBM Financial Transaction Manager (FTM), a transaction processing system for financial organizations, transmits sensitive information in cleartext, allowing remote attackers to intercept and read confidential data. This vulnerability exposes authentication credentials, account details, and payment information without encryption protection.
Technical details
The vulnerability stems from cleartext transmission of sensitive data, allowing network-level interception. An unauthenticated remote attacker can passively capture transmitted information via network sniffing or man-in-the-middle positioning. The advisory references CVE-2026-18134 with a CVSS score of 7.5, indicating high-risk information disclosure without requiring authentication or user interaction.
Affected products
- IBM Financial Transaction Manager <UNKNOWN>
Timeline
- 2026-09-22: disclosed