Executive brief
IBM Financial Transaction Manager is middleware that processes financial transactions in enterprise environments. An authenticated attacker can exploit hardcoded cryptographic keys and initialization vectors to forge authentication tags and decrypt sensitive transaction data, compromising the integrity and confidentiality of financial operations.
Technical details
This vulnerability stems from the use of hardcoded cryptographic keys and initialization vectors in FTM's authentication mechanism (CWE-327). An authenticated network attacker can leverage these static credentials to forge authentication tags and obtain sensitive information without user interaction. A fix is available from IBM.
Affected products
- IBM Financial Transaction Manager 4.x
Timeline
- 2026-09-22: disclosed