Executive brief
IBM Financial Transaction Manager (FTM), a financial transaction processing platform for OpenShift environments, uses hard-coded or predictable cryptographic keys to protect sensitive data. A remote attacker can exploit this weakness to decrypt communications and extract confidential financial information without authentication.
Technical details
The vulnerability stems from use of hard-coded or predictable cryptographic keys in IBM FTM, allowing a remote unauthenticated attacker to obtain sensitive information through cryptographic attacks. The attack is network-accessible and requires no authentication, user interaction, or special conditions. An attacker gaining knowledge of or predicting the key material can decrypt sensitive data and forge authentication tokens.
Affected products
- IBM Financial Transaction Manager
Timeline
- 2026-09-22: disclosed