Executive brief
IBM Financial Transaction Manager (FTM), which processes financial transactions and payments on RedHat OpenShift, contains a flaw that allows remote attackers to forge validly-signed messages by bypassing cryptographic signature verification. An attacker exploiting this could impersonate legitimate payment instructions, modify transactions, or inject fraudulent financial messages without detection, potentially leading to unauthorized fund transfers or system compromise.
Technical details
The vulnerability stems from improper verification of cryptographic signatures in FTM, allowing an attacker to forge validly-signed messages and bypass signature validation controls. The attack is network-accessible and requires no authentication or special preconditions. Successful exploitation grants the attacker the ability to fabricate trusted messages and compromise transaction integrity.
Affected products
- IBM Financial Transaction Manager
Timeline
- 2026-09-22: disclosed