CVE-2018-1670
Description
IBM Financial Transaction Manager for ACH Services for Multi-Platform 3.0.2 could allow an authenticated user to obtain sensitive product configuration information from log files. IBM X-Force ID: 144946.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
IBM Financial Transaction Manager for ACH and Check Services log files expose sensitive configuration data to authenticated users, leading to low-severity information disclosure.
Vulnerability
IBM Financial Transaction Manager (FTM) for ACH Services (v3.0.2.0–3.0.2.1) and for Check Services (v3.0.0.0–3.0.0.15, v3.0.2.0–3.0.2.1, v3.0.5.0–3.0.5.1) on Multi-Platform write sensitive product configuration information into log files. An authenticated user with access to these logs can read the configuration data. [1][2]
Exploitation
An attacker must have valid authentication credentials to the FTM system and the ability to read log files (e.g., via file access or log viewing interfaces). No special privileges beyond authentication are required; the vulnerability is triggered simply by accessing the log files that contain the configuration details. [1][2]
Impact
Successful exploitation results in the disclosure of sensitive product configuration information, which could aid an attacker in further attacks. The CVSS v3.0 base score is 3.1 (Low), with a vector of AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N, indicating low confidentiality impact and no integrity or availability impact. [1][2]
Mitigation
IBM has not provided a fix or workaround in the available references. The security bulletins state "None" under Workarounds and Mitigations. Affected users should monitor IBM's support pages for future updates. [1][2]
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: =3.0.2
- Range: 3.0.2
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- www.ibm.com/support/docview.wssmitrex_refsource_CONFIRM
- www.ibm.com/support/docview.wssmitrex_refsource_CONFIRM
- exchange.xforce.ibmcloud.com/vulnerabilities/144946mitrevdb-entryx_refsource_XF
News mentions
0No linked articles in our index yet.