medium · CVSS v3 5.3
CVE-2026-17620
IBM Financial Transaction Manager (FTM) for RedHat OpenShift versions 4.0.6.0 through 4.0.10 transmits sensitive or security‑critical data i
Overview
IBM Financial Transaction Manager (FTM) for RedHat OpenShift versions 4.0.6.0 through 4.0.10 transmits sensitive or security‑critical data in cleartext over a network channel. This allows attackers to sniff and potentially intercept confidential transaction information. The vulnerability is identified as CVE-2026-17620 with medium severity.
Description
IBM Financial Transaction Manager (FTM) for RedHat OpenShift 4.0.6.0 through 4.0.6.0.0.6.0 Refresh (Operator 4.4.6+20260807.081800)4.0.7.04.0.8.04.0.9.04.0.10.0 Interim Fix 064 IBM Financial Transaction Manager transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
Impact
Confidentiality of transaction data is at risk; attackers could capture sensitive financial information, potentially leading to fraud or data leakage. The risk primarily affects organizations running IBM FTM on RedHat OpenShift, especially those handling financial transactions.
Remediation
Apply the interim fix 064 or upgrade to a patched version; configure FTM to use TLS/SSL for all communication; enforce network segmentation and monitoring to detect sniffing; update the OpenShift operator to the latest stable release.
Risk context
With a CVSS v3 score of 5.3 and no EPSS data, the risk is moderate but warrants timely remediation to protect sensitive financial data.
Affected products
- IBM Financial Transaction Manager for RedHat OpenShift 4.0.6.0
- IBM FTM Operator 4.4.6+
- IBM FTM 4.0.7
- IBM FTM 4.0.8
- IBM FTM 4.0.9
- IBM FTM 4.0.10
Scores
- Severity
- medium
- CVSS v2
- 4.6
- CVSS v3
- 5.3
- CVSS v4
- —
- EPSS
- —