rootpwn

medium · CVSS v3 5.3

CVE-2026-17620

IBM Financial Transaction Manager (FTM) for RedHat OpenShift versions 4.0.6.0 through 4.0.10 transmits sensitive or security‑critical data i

Overview

IBM Financial Transaction Manager (FTM) for RedHat OpenShift versions 4.0.6.0 through 4.0.10 transmits sensitive or security‑critical data in cleartext over a network channel. This allows attackers to sniff and potentially intercept confidential transaction information. The vulnerability is identified as CVE-2026-17620 with medium severity.

Description

IBM Financial Transaction Manager (FTM) for RedHat OpenShift 4.0.6.0 through 4.0.6.0.0.6.0 Refresh (Operator 4.4.6+20260807.081800)4.0.7.04.0.8.04.0.9.04.0.10.0 Interim Fix 064 IBM Financial Transaction Manager transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

Impact

Confidentiality of transaction data is at risk; attackers could capture sensitive financial information, potentially leading to fraud or data leakage. The risk primarily affects organizations running IBM FTM on RedHat OpenShift, especially those handling financial transactions.

Remediation

Apply the interim fix 064 or upgrade to a patched version; configure FTM to use TLS/SSL for all communication; enforce network segmentation and monitoring to detect sniffing; update the OpenShift operator to the latest stable release.

Risk context

With a CVSS v3 score of 5.3 and no EPSS data, the risk is moderate but warrants timely remediation to protect sensitive financial data.

Affected products

  • IBM Financial Transaction Manager for RedHat OpenShift 4.0.6.0
  • IBM FTM Operator 4.4.6+
  • IBM FTM 4.0.7
  • IBM FTM 4.0.8
  • IBM FTM 4.0.9
  • IBM FTM 4.0.10

Scores

Severity
medium
CVSS v2
4.6
CVSS v3
5.3
CVSS v4
EPSS

confidentiality IBM FTM RedHat OpenShift cleartext network-sniffing medium patch

← All CVEs