high · CVSS v3 8.8
CVE-2026-17637
IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to arbitrary code execution via deserialization of untrusted data
Overview
IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to arbitrary code execution via deserialization of untrusted data. An attacker on an adjacent network can exploit this flaw to run malicious code on the FTM instance. The vulnerability could compromise transaction integrity and confidentiality.
Description
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow an adjacent-network attacker to execute arbitrary code due to deserialization of untrusted data.
Impact
The flaw threatens confidentiality, integrity, and availability of financial transaction data. Attackers can gain unauthorized code execution on FTM pods, potentially exposing sensitive transaction records. Defenders of IBM FTM deployments on OpenShift should treat this as a critical risk to transaction integrity.
Remediation
Apply the latest IBM security patch for FTM immediately. Restrict network access to FTM pods using OpenShift network policies, limiting exposure to adjacent networks. Disable or sanitize deserialization of untrusted data in application configuration, and monitor for anomalous process activity.
Risk context
Severity is high with a CVSS v3 score of 8.8. No EPSS data is available, but the high score indicates significant risk if left unpatched.
Affected products
- IBM FTM
- IBM Financial Transaction Manager
- IBM FTM RedHat OpenShift
Scores
- Severity
- high
- CVSS v2
- 8.3
- CVSS v3
- 8.8
- CVSS v4
- —
- EPSS
- —