Where
AND
-Infinity
0
Severity
8.8
AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

IBM Financial Transaction Manager (FTM) could allow a local attacker to gain unauthorized access to sensitive information and modify transaction data due to the use of hard-coded credentials.

1 / 2
Source: IBM
First published (updated )
Severity
8.8
AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

IBM Financial Transaction Manager (FTM) could allow a local attacker to obtain sensitive information and perform unauthorized actions due to insufficiently protected credentials.

1 / 2
Source: IBM
First published (updated )
Severity
8.8
AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

IBM Financial Transaction Manager (FTM) could allow a local attacker to execute arbitrary commands due to the inclusion of functionality from an untrusted control sphere.

1 / 2
Source: IBM
First published (updated )
Severity
8.8
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

IBM Financial Transaction Manager (FTM) 4.x is vulnerable to unauthenticated remote code execution via Java native deserialization on the PayDir Business Rules Manager RMI SSL endpoint (BrmRMISSLServerSocketFactory.java:95, EP8). An adjacent-network attacker can deliver a crafted serialized payload to achieve arbitrary code execution, exposing all PayDir credentials and enabling manipulation of payment business rules.

1 / 2
Source: IBM
First published (updated )
Severity
8.8
Buffer Overflow
AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H

IBM Financial Transaction Manager (FTM) could allow a remote authenticated attacker to execute arbitrary code due to a buffer overflow.

1 / 2
Source: IBM
First published (updated )
Severity
8.8
AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow an adjacent-network attacker to execute arbitrary code due to deserialization of untrusted data.

1 / 2
Source: MITRE
First published (updated )
Severity
8.8
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

IBM Financial Transaction Manager (FTM) could allow a remote authenticated attacker to execute arbitrary code due to improper validation of a specified quantity.

1 / 2
Source: IBM
First published (updated )
Severity
8.8
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

IBM Financial Transaction Manager 3.2.4 does not invalidate session any existing session identifier gives an attacker the opportunity to steal authenticated sessions. IBM X-Force ID: 215040.

1 / 2
First published (updated )
Severity
8.8
CSRF
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

IBM Financial Transaction Manager 3.2.4 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 214210.

1 / 2
First published (updated )
Severity
8.8
CSRF
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

IBM Financial Transaction Manager for Digital Payments for Multi-Platform 3.0.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 148944.

First published (updated )
Severity
8.8
SQL Injection
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

IBM Financial Transaction Manager (FTM) for Multi-Platform (MP) 3.0.0.0 through 3.0.0.7 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 132926.

First published (updated )
Severity
8.8
Input Validation
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

IBM Financial Transaction Manager 3.2.0 through 3.2.10 could allow an authenticated user to perform unauthorized actions due to improper validation. IBM X-Force ID: 192954.

1 / 3
Source: MITRE
First published (updated )
Severity
8.5
XEE
AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N

IBM Financial Transaction Manager (FTM) could allow a remote authenticated attacker to obtain sensitive information due to improper restriction of XML external entity references.

1 / 2
Source: IBM
First published (updated )
Severity
8.2
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L

IBM Financial Transaction Manager (FTM) could allow a remote attacker to manipulate database queries due to improper neutralization of special elements in a boolean expression.

1 / 2
Source: IBM
First published (updated )
Severity
8.2
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L

IBM Financial Transaction Manager (FTM) could allow a remote attacker to perform unauthorized actions due to improper authentication and missing authorization.

1 / 2
Source: IBM
First published (updated )
Severity
8.2
XSS
AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:H/A:N

IBM Financial Transaction Manager (FTM) could allow a remote attacker to execute arbitrary JavaScript in an authenticated user's browser due to improper neutralization of HTML input.

1 / 2
Source: IBM
First published (updated )
Severity
8.1
SQL Injection
AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

IBM Financial Transaction Manager (FTM) could allow a remote attacker to execute arbitrary ESQL commands due to improper neutralization of special elements used in an ESQL command.

1 / 2
Source: IBM
First published (updated )
Severity
8.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

IBM Financial Transaction Manager (FTM) could allow a remote attacker to bypass authentication and access sensitive information due to a hard-coded cryptographic key.

1 / 2
Source: IBM
First published (updated )
Severity
8
AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N

IBM Financial Transaction Manager (FTM) could allow a remote attacker to obtain sensitive information due to the use of a hard-coded or predictable cryptographic key.

1 / 2
Source: IBM
First published (updated )
Severity
8
CSRF
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

Cross-site request forgery (CSRF) vulnerability in IBM Financial Transaction Manager (FTM) for ACH Services for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013, Financial Transaction Manager (FTM) for Check Services for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013, and Financial Transaction Manager (FTM) for Corporate Payment Services (CPS) for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013 allows remote attackers to hijack the authentication of arbitrary users via unspecified vectors. IBM X-Force ID: 111052.

First published (updated )
Severity
7.9
SSRF
AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N

IBM Financial Transaction Manager (FTM) could allow a local attacker to obtain sensitive information and trigger unauthorized actions due to server-side request forgery.

1 / 2
Source: IBM
First published (updated )
Severity
7.6
AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H

IBM Financial Transaction Manager (FTM) could allow a remote attacker to cause a denial of service due to the improper use of reflection with externally controlled input.

1 / 2
Source: IBM
First published (updated )
Severity
7.5
Path Traversal
AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

IBM Financial Transaction Manager (FTM) could allow a remote attacker to read arbitrary files due to improper path canonicalization.

1 / 2
Source: IBM
First published (updated )
Severity
7.5
AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

IBM Financial Transaction Manager (FTM) could allow a remote attacker to obtain sensitive information due to cleartext transmission of sensitive information.

1 / 2
Source: IBM
First published (updated )
Severity
7.5
AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N

FTM 4.x ALL could allow a remote authenticated attacker to obtain sensitive information due to an XML external entity injection flaw.

1 / 2
Source: IBM
First published (updated )
Severity
7.5
Path Traversal
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

IBM Financial Transaction Manager 3.2.0 through 3.2.7 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 192953.

1 / 3
Source: MITRE
First published (updated )
Severity
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

IBM Financial Transaction Manager for Digital Payments for Multi-Platform 3.2.0 through 3.2.7 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 193662.

1 / 3
Source: MITRE
First published (updated )
Severity
7.5
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the Message Entry and Repair (MER) facility of Financial Transaction Manager for SWIFT Services the sending address and the message type of FIN messages are assumed to be immutable. However, an attacker might modify these elements of a business transaction.

1 / 2
Source: IBM
First published (updated )
Severity
7.4
AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

IBM Financial Transaction Manager (FTM) could allow a remote attacker to obtain sensitive information due to cleartext transmission of sensitive information.

1 / 2
Source: IBM
First published (updated )
Severity
7.4
XEE
AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

IBM Financial Transaction Manager (FTM) could allow a remote attacker to obtain sensitive information due to improper restriction of XML external entity references.

1 / 2
Source: IBM
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203