critical · CVSS v3 9.1
CVE-2026-17635
IBM Financial Transaction Manager (FTM) on RedHat OpenShift contains a critical flaw that allows remote attackers to bypass HTTP method rest
Overview
IBM Financial Transaction Manager (FTM) on RedHat OpenShift contains a critical flaw that allows remote attackers to bypass HTTP method restrictions and perform unauthorized actions. The vulnerability stems from misconfigured security constraints that fail to enforce proper method validation. It can lead to unauthorized data manipulation or system compromise.
Description
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to perform unauthorized actions due to improper configuration of HTTP method-based security constraints.
Impact
The flaw violates confidentiality by allowing attackers to read sensitive transaction data, integrity by enabling unauthorized modifications, and availability by potentially disrupting service. Administrators and end users of the FTM platform are directly impacted.
Remediation
Apply the latest IBM FTM patch or upgrade to the most recent release that corrects the HTTP method constraint handling. Verify that only allowed HTTP methods (e.g., GET, POST, PUT, DELETE) are enabled for each endpoint and disable or restrict others. Implement network segmentation and firewall rules to limit exposure of the FTM API surface, and enable logging and monitoring to detect anomalous method usage.
Risk context
The CVSS v3 score of 9.1 and critical severity indicate a high risk that could be exploited remotely. Defenders should treat this as an urgent priority and apply mitigations promptly.
Affected products
- IBM FTM
- RedHat OpenShift
Scores
- Severity
- critical
- CVSS v2
- 9.4
- CVSS v3
- 9.1
- CVSS v4
- —
- EPSS
- —