VYPR

Financial Transaction Manager

by IBM

CVEs (104)

  • CVE-2026-18169CriSep 22, 2026
    risk 0.64cvss 9.9epss 0.01

    IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to obtain sensitive information due to improper validation of symbolic links.

  • CVE-2026-18163CriSep 22, 2026
    risk 0.64cvss 9.8epss 0.01

    IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute arbitrary code due to improper deserialization of untrusted data.

  • CVE-2026-18162CriSep 22, 2026
    risk 0.64cvss 9.8epss 0.00

    IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute arbitrary code due to improper neutralization of user-controlled input within the new Function constructor.

  • CVE-2019-4575CriJun 15, 2022
    risk 0.64cvss 9.8epss 0.01

    IBM Financial Transaction Manager for Digital Payments for Multi-Platform 3.2.0 through 3.2.9 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end…

  • CVE-2019-4032CriMar 5, 2019
    risk 0.64cvss 9.8epss 0.02

    IBM Financial Transaction Manager for Digital Payments for Multi-Platform 3.1.0 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM…

  • CVE-2026-18872CriSep 23, 2026
    risk 0.60cvss 9.3epss 0.00

    IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to stored cross-site scripting (CWE-79) in the FTM UI NetworkAcknowledgement React component (NetworkAcknowledgement.jsx:42). A malicious actor can inject script into stored network acknowledgement data…

  • CVE-2026-17645CriSep 22, 2026
    risk 0.59cvss 9.1epss 0.00

    IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to gain elevated privileges due to improper privilege management.

  • CVE-2026-17635CriSep 22, 2026
    risk 0.59cvss 9.1epss 0.00

    IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to perform unauthorized actions due to improper configuration of HTTP method-based security constraints.

  • CVE-2020-5003CriJun 11, 2021
    risk 0.59cvss 9.1epss 0.02

    IBM Financial Transaction Manager 3.2.4 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 192956.

  • CVE-2026-18490HigSep 23, 2026
    risk 0.57cvss 8.8epss 0.00

    IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to unauthenticated remote code execution via Java native deserialization on the PayDir Business Rules Manager RMI SSL endpoint (BrmRMISSLServerSocketFactory.java:95, EP8). An adjacent-network attacker can…

  • CVE-2026-17647HigSep 22, 2026
    risk 0.57cvss 8.8epss 0.00

    IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a local attacker to execute arbitrary commands due to the inclusion of functionality from an untrusted control sphere.

  • CVE-2026-17644HigSep 22, 2026
    risk 0.57cvss 8.8epss 0.00

    IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a local attacker to gain unauthorized access to sensitive information and modify transaction data due to the use of hard-coded credentials.

  • CVE-2026-17643HigSep 22, 2026
    risk 0.57cvss 8.8epss 0.00

    IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a local attacker to obtain sensitive information and perform unauthorized actions due to insufficiently protected credentials.

  • CVE-2026-17637HigSep 22, 2026
    risk 0.57cvss 8.8epss 0.00

    IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow an adjacent-network attacker to execute arbitrary code due to deserialization of untrusted data.

  • CVE-2026-17636HigSep 22, 2026
    risk 0.57cvss 8.8epss 0.01

    IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to execute arbitrary code due to improper validation of a specified quantity.

  • CVE-2021-39066HigFeb 2, 2022
    risk 0.57cvss 8.8epss 0.01

    IBM Financial Transaction Manager 3.2.4 does not invalidate session any existing session identifier gives an attacker the opportunity to steal authenticated sessions. IBM X-Force ID: 215040.

  • CVE-2021-39044HigFeb 2, 2022
    risk 0.57cvss 8.8epss 0.00

    IBM Financial Transaction Manager 3.2.4 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 214210.

  • CVE-2017-1606HigDec 11, 2017
    risk 0.57cvss 8.8epss 0.01

    IBM Financial Transaction Manager (FTM) for Multi-Platform (MP) 3.0.0.0 through 3.0.0.7 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end…

  • CVE-2026-18095HigSep 22, 2026
    risk 0.55cvss 8.5epss 0.00

    IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to execute arbitrary code due to a buffer overflow.

  • CVE-2026-17646HigSep 22, 2026
    risk 0.55cvss 8.5epss 0.00

    IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to obtain sensitive information due to improper restriction of XML external entity references.

Page 1 of 6