rootpwn

high · CVSS v3 8.8

CVE-2026-17637

IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to arbitrary code execution via deserialization of untrusted data

Overview

IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to arbitrary code execution via deserialization of untrusted data. An attacker on an adjacent network can exploit this flaw to run malicious code on the FTM instance. The vulnerability could compromise transaction integrity and confidentiality.

Description

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow an adjacent-network attacker to execute arbitrary code due to deserialization of untrusted data.

Impact

The flaw threatens confidentiality, integrity, and availability of financial transaction data. Attackers can gain unauthorized code execution on FTM pods, potentially exposing sensitive transaction records. Defenders of IBM FTM deployments on OpenShift should treat this as a critical risk to transaction integrity.

Remediation

Apply the latest IBM security patch for FTM immediately. Restrict network access to FTM pods using OpenShift network policies, limiting exposure to adjacent networks. Disable or sanitize deserialization of untrusted data in application configuration, and monitor for anomalous process activity.

Risk context

Severity is high with a CVSS v3 score of 8.8. No EPSS data is available, but the high score indicates significant risk if left unpatched.

Affected products

  • IBM FTM
  • IBM Financial Transaction Manager
  • IBM FTM RedHat OpenShift

Scores

Severity
high
CVSS v2
8.3
CVSS v3
8.8
CVSS v4
EPSS

IBM FTM OpenShift Deserialization Remote Code Execution High Severity Network

← All CVEs