Executive brief
IBM Financial Transaction Manager (FTM) is a payment processing and transaction management system used by financial institutions. A remote attacker can execute arbitrary code on the system by supplying specially crafted input that is not properly validated before being used in a Function constructor, allowing complete system compromise.
Technical details
The vulnerability is a code injection flaw in the Function constructor where user-controlled input is not properly sanitized. An unauthenticated remote attacker can craft a malicious request that exploits this improper neutralization to execute arbitrary code with the privileges of the FTM application. Exploitation does not require authentication or user interaction and can be triggered directly over the network.
Affected products
- IBM Financial Transaction Manager
Timeline
- 2026-09-22: disclosed