Executive brief
IBM Financial Transaction Manager (FTM) is middleware that processes payment and financial transactions for large enterprises. A remote attacker can exploit improper deserialization of untrusted data to execute arbitrary code on the system, potentially gaining full control of financial transaction processing, data theft, and system compromise. This vulnerability requires no authentication and can be triggered over the network.
Technical details
A deserialization vulnerability in IBM FTM allows remote code execution when the application deserializes untrusted data without proper validation. An attacker can craft malicious serialized objects that execute arbitrary code during the deserialization process. The vulnerability is remotely exploitable over the network with no authentication required.
Affected products
- IBM Financial Transaction Manager
Timeline
- 2026-09-22: disclosed