CVE-2026-17644: IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities
IBM Financial Transaction Manager (FTM) could allow a local attacker to gain unauthorized access to sensitive information and modify transaction data due to the use of hard-coded credentials.
Other sources
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a local attacker to gain unauthorized access to sensitive information and modify transaction data due to the use of hard-coded credentials.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Financial Transaction Manager (FTM) for Red Hat OpenShiftto a version that resolves this vulnerability.Fixed in 4.0.11.0
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The issue is described as exploitable by a local attacker, so the attacker would need local access to the affected IBM Financial Transaction Manager for RedHat OpenShift environment.
What could an attacker do if they exploit the hard-coded credentials?
An attacker could gain unauthorized access to sensitive information and modify transaction data.