rootpwn

critical · CVSS v3 9.1

CVE-2026-17635

IBM Financial Transaction Manager (FTM) on RedHat OpenShift contains a critical flaw that allows remote attackers to bypass HTTP method rest

Overview

IBM Financial Transaction Manager (FTM) on RedHat OpenShift contains a critical flaw that allows remote attackers to bypass HTTP method restrictions and perform unauthorized actions. The vulnerability stems from misconfigured security constraints that fail to enforce proper method validation. It can lead to unauthorized data manipulation or system compromise.

Description

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to perform unauthorized actions due to improper configuration of HTTP method-based security constraints.

Impact

The flaw violates confidentiality by allowing attackers to read sensitive transaction data, integrity by enabling unauthorized modifications, and availability by potentially disrupting service. Administrators and end users of the FTM platform are directly impacted.

Remediation

Apply the latest IBM FTM patch or upgrade to the most recent release that corrects the HTTP method constraint handling. Verify that only allowed HTTP methods (e.g., GET, POST, PUT, DELETE) are enabled for each endpoint and disable or restrict others. Implement network segmentation and firewall rules to limit exposure of the FTM API surface, and enable logging and monitoring to detect anomalous method usage.

Risk context

The CVSS v3 score of 9.1 and critical severity indicate a high risk that could be exploited remotely. Defenders should treat this as an urgent priority and apply mitigations promptly.

Affected products

  • IBM FTM
  • RedHat OpenShift

Scores

Severity
critical
CVSS v2
9.4
CVSS v3
9.1
CVSS v4
EPSS

IBM FTM RedHat OpenShift HTTP-method critical confidentiality

← All CVEs