Executive brief
IBM Financial Transaction Manager is a platform that processes and manages financial transactions in enterprise environments. An authenticated attacker can bypass security controls and forge the identities of other users, potentially allowing them to perform unauthorized financial actions or access sensitive data on behalf of legitimate users.
Technical details
The vulnerability stems from improper authorization checks (CWE-862) that allow an authenticated remote attacker to forge user identities and bypass security controls. The flaw requires the attacker to be already authenticated to the system; no additional user interaction or complex setup is needed. An attacker can escalate privileges or impersonate other users to perform sensitive operations.
Affected products
- IBM Financial Transaction Manager
Timeline
- 2026-09-22: disclosed