rootpwn

high · CVSS v3 7.3

CVE-2026-17618

IBM Financial Transaction Manager (FTM) for RedHat OpenShift has a remote unauthenticated vulnerability that allows attackers to read and mo

Overview

IBM Financial Transaction Manager (FTM) for RedHat OpenShift has a remote unauthenticated vulnerability that allows attackers to read and modify sensitive data and cause denial of service. The flaw stems from improper authorization checks in the web interface. It can be exploited without credentials, exposing critical financial transaction information.

Description

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote unauthenticated attacker to view and modify sensitive information and cause a denial of service due to improper authorization.

Impact

Confidentiality: attackers can view confidential transaction data. Integrity: attackers can alter transaction records. Availability: potential denial of service. Defenders include system administrators and security teams managing FTM deployments.

Remediation

Apply the latest IBM FTM security patch or upgrade to a version that fixes the authorization issue. Restrict network access to the FTM API endpoints using firewalls or OpenShift network policies. Enforce strong authentication and role-based access controls, and monitor logs for suspicious activity.

Risk context

Severity is high with a CVSS v3 score of 7.3. The lack of an EPSS score suggests no current widespread exploitation data, but the high severity warrants prompt remediation.

Affected products

  • IBM FTM
  • RedHat OpenShift

Scores

Severity
high
CVSS v2
7.5
CVSS v3
7.3
CVSS v4
EPSS

ibm ftm openshift unauthenticated authorization denialofservice confidentiality

← All CVEs