CVE-2026-18132: IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities
IBM Financial Transaction Manager (FTM) could allow a remote authenticated attacker to perform unauthorized payment mutation actions due to missing authorization.
Other sources
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to perform unauthorized payment mutation actions due to missing authorization.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Financial Transaction Manager (FTM) for Red Hat OpenShiftto a version that resolves this vulnerability.Fixed in 4.0.11.0
Event History
Frequently Asked Questions
What level of access does an attacker need?
An attacker must be remotely authenticated to exploit the missing authorization issue.
What actions could an attacker perform?
A successful attacker could perform unauthorized payment mutation actions.
Which deployment is identified as affected?
The affected software identified is IBM Financial Transaction Manager for RedHat OpenShift.