IBM
IBM Financial Transaction Manager: vulnerabilidades y CVE
IBM Financial Transaction Manager tiene 92 vulnerabilidades publicadas, 46 de ellas en los últimos 12 meses. 10 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE92
Últimos 12 meses46
Críticas10
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-19267 | Media (6.2) | 0.13% | — | 23 sept 2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to missing authentication on the Business Rules Manager commands REST endpoint (`CommandsResource.java:31`). A local actor can invoke… |
| CVE-2026-19179 | Alta (8.2) | 0.30% | — | 23 sept 2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to manipulate database queries due to improper neutralization of special elements in a boolean expression. |
| CVE-2026-19087 | Media (4.4) | 0.09% | — | 23 sept 2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a local attacker to achieve privilege escalation within the container due to improper privilege management. |
| CVE-2026-18875 | Alta (7.3) | 0.22% | — | 23 sept 2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to RAG poisoning via unauthenticated runbook upsert (CWE-74) in the FTM AI agent server (api.vectordb.runbooks.js:51). An unauthenticated… |
| CVE-2026-18872 | Crítica (9.3) | 0.19% | — | 23 sept 2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to stored cross-site scripting (CWE-79) in the FTM UI NetworkAcknowledgement React component (NetworkAcknowledgement.jsx:42). A malicious actor… |
| CVE-2026-18505 | Media (5.4) | 0.15% | — | 23 sept 2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to open redirect in the PMP `HostHeaderFilter` (`HostHeaderFilter.java:151`). An unauthenticated attacker can craft a request with a manipulated… |
| CVE-2026-18490 | Alta (8.8) | 0.25% | — | 23 sept 2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to unauthenticated remote code execution via Java native deserialization on the PayDir Business Rules Manager RMI SSL endpoint… |
| CVE-2026-18185 | Alta (7.3) | 0.26% | — | 23 sept 2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to access sensitive information and modify system configurations due to missing authentication for a critical function. |
| CVE-2026-18184 | Alta (7.4) | 0.22% | — | 23 sept 2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive information due to an XML external entity (XXE) injection flaw. |
| CVE-2026-18181 | Alta (8.1) | 0.25% | — | 23 sept 2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to bypass authentication and access sensitive information due to a hard-coded cryptographic key. |
| CVE-2026-18180 | Media (6.5) | 0.27% | — | 23 sept 2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to obtain sensitive information due to SQL injection. |
| CVE-2026-18179 | Media (6.5) | 0.24% | — | 23 sept 2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to clear active chat sessions due to improper authorization. |
| CVE-2026-18177 | Alta (7.1) | 0.18% | — | 23 sept 2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute unauthorized payment actions due to missing authorization checks. |
| CVE-2026-18176 | Alta (7.4) | 0.13% | — | 22 sept 2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive information due to cleartext transmission of sensitive information. |
| CVE-2026-18173 | Baja (3.7) | 0.24% | — | 22 sept 2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive information due to improper enforcement of mutual TLS authentication. |
| CVE-2026-18172 | Alta (7.4) | 0.20% | — | 22 sept 2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive information due to improper restriction of XML external entity references. |
| CVE-2026-18170 | Media (6.5) | 0.19% | — | 22 sept 2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to cause a denial of service due to allocation of resources without limits or throttling. |
| CVE-2026-18169 | Crítica (9.9) | 0.53% | — | 22 sept 2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to obtain sensitive information due to improper validation of symbolic links. |
| CVE-2026-18163 | Crítica (9.8) | 0.51% | — | 22 sept 2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute arbitrary code due to improper deserialization of untrusted data. |
| CVE-2026-18162 | Crítica (9.8) | 0.48% | — | 22 sept 2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute arbitrary code due to improper neutralization of user-controlled input within the new Function constructor. |
| CVE-2026-18161 | Media (4.3) | 0.20% | — | 22 sept 2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to falsify transaction audit logs due to improper validation of a client-supplied HTTP header. |
| CVE-2026-18156 | Media (6.5) | 0.24% | — | 22 sept 2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to bypass security controls by forging user identities due to improper authorization. |
| CVE-2026-18154 | Alta (8) | 0.17% | — | 22 sept 2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive information due to the use of a hard-coded or predictable cryptographic key. |
| CVE-2026-18153 | Media (5.4) | 0.14% | — | 22 sept 2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to obtain sensitive information and forge authentication tags due to the use of hard-coded cryptographic keys and… |
| CVE-2026-18152 | Alta (7.4) | 0.12% | — | 22 sept 2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to forge validly-signed messages due to improper verification of cryptographic signatures. |
| CVE-2026-18137 | Alta (8.1) | 0.30% | — | 22 sept 2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute arbitrary ESQL commands due to improper neutralization of special elements used in an ESQL command. |
| CVE-2026-18134 | Alta (7.5) | 0.13% | — | 22 sept 2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive information due to cleartext transmission of sensitive information. |
| CVE-2026-18133 | Media (5.4) | 0.30% | — | 22 sept 2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to modify server files due to path traversal. |
| CVE-2026-18132 | Media (6.5) | 0.21% | — | 22 sept 2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to perform unauthorized payment mutation actions due to missing authorization. |
| CVE-2026-18131 | Alta (8.2) | 0.25% | — | 22 sept 2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute arbitrary JavaScript in an authenticated user's browser due to improper neutralization of HTML input. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.
Otros productos de IBM
AIX · 551Websphere Application Server · 519DB2 · 355Vios · 237Sterling B2B Integrator · 205I · 203Rational Quality Manager · 202Qradar Security Information AND Event Manager · 192Infosphere Information Server · 189Maximo Asset Management · 182Rational Doors Next Generation · 153Rational Team Concert · 142