IBM Financial Transaction Manager (FTM) could allow a remote attacker to obtain sensitive information due to the use of a hard-coded or predictable cryptographic key.
IBM Financial Transaction Manager (FTM) could allow a remote authenticated attacker to obtain sensitive information and forge authentication tags due to the use of hard-coded cryptographic keys and initialization vectors.
FTM 4.x ALL could allow a remote authenticated attacker to obtain sensitive information due to an XML external entity injection flaw.
IBM Financial Transaction Manager (FTM) could allow a remote authenticated attacker to execute arbitrary code due to improper validation of a specified quantity.
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow an adjacent-network attacker to execute arbitrary code due to deserialization of untrusted data.
IBM Financial Transaction Manager (FTM) could allow a local attacker to obtain sensitive information and perform unauthorized actions due to insufficiently protected credentials.
IBM Financial Transaction Manager (FTM) could allow a local attacker to gain unauthorized access to sensitive information and modify transaction data due to the use of hard-coded credentials.
IBM Financial Transaction Manager (FTM) could allow a remote authenticated attacker to obtain sensitive information due to improper restriction of XML external entity references.
IBM Financial Transaction Manager (FTM) could allow a local attacker to execute arbitrary commands due to the inclusion of functionality from an untrusted control sphere.
IBM Financial Transaction Manager (FTM) could allow a local attacker to obtain sensitive information and trigger unauthorized actions due to server-side request forgery.
IBM Financial Transaction Manager (FTM) could allow a remote attacker to perform unauthorized actions due to improper authentication and missing authorization.
IBM Financial Transaction Manager (FTM) could allow a remote authenticated attacker to execute arbitrary code due to a buffer overflow.
IBM Financial Transaction Manager (FTM) could allow a remote attacker to read arbitrary files due to improper path canonicalization.
IBM Financial Transaction Manager (FTM) could allow a remote attacker to cause a denial of service due to the improper use of reflection with externally controlled input.
IBM Financial Transaction Manager (FTM) could allow a remote attacker to execute arbitrary JavaScript in an authenticated user's browser due to improper neutralization of HTML input.
IBM Financial Transaction Manager (FTM) could allow a remote attacker to obtain sensitive information due to cleartext transmission of sensitive information.
IBM Financial Transaction Manager (FTM) could allow a remote attacker to obtain sensitive information due to cleartext transmission of sensitive information.
IBM Financial Transaction Manager (FTM) could allow a remote attacker to obtain sensitive information due to improper restriction of XML external entity references.
IBM Financial Transaction Manager (FTM) could allow a remote attacker to execute arbitrary ESQL commands due to improper neutralization of special elements used in an ESQL command.
IBM Financial Transaction Manager (FTM) could allow a remote attacker to execute unauthorized payment actions due to missing authorization checks.
IBM Financial Transaction Manager (FTM) could allow a remote attacker to bypass authentication and access sensitive information due to a hard-coded cryptographic key.
IBM Financial Transaction Manager (FTM) could allow a remote attacker to obtain sensitive information due to an XML external entity (XXE) injection flaw.
IBM Financial Transaction Manager (FTM) could allow a remote attacker to access sensitive information and modify system configurations due to missing authentication for a critical function.
IBM Financial Transaction Manager (FTM) 4.x is vulnerable to unauthenticated remote code execution via Java native deserialization on the PayDir Business Rules Manager RMI SSL endpoint (BrmRMISSLServerSocketFactory.java:95, EP8). An adjacent-network attacker can deliver a crafted serialized payload to achieve arbitrary code execution, exposing all PayDir credentials and enabling manipulation of payment business rules.
IBM Financial Transaction Manager (FTM) 4.x is vulnerable to RAG poisoning via unauthenticated runbook upsert (CWE-74) in the FTM AI agent server (api.vectordb.runbooks.js:51). An unauthenticated attacker can insert malicious runbook content into the agent's vector database to steer AI-driven MCP tool calls, potentially triggering unauthorized payment actions or exfiltrating payment data.
IBM Financial Transaction Manager (FTM) could allow a remote attacker to manipulate database queries due to improper neutralization of special elements in a boolean expression.
IBM Financial Transaction Manager 3.2.0 through 3.2.7 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 192953.
IBM Financial Transaction Manager 3.2.0 through 3.2.10 could allow an authenticated user to perform unauthorized actions due to improper validation. IBM X-Force ID: 192954.
IBM Financial Transaction Manager for Digital Payments for Multi-Platform 3.2.0 through 3.2.7 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 193662.
IBM Financial Transaction Manager 3.2.4 does not invalidate session any existing session identifier gives an attacker the opportunity to steal authenticated sessions. IBM X-Force ID: 215040.