high · CVSS v3 8.8
CVE-2026-17643
IBM Financial Transaction Manager (FTM) on RedHat OpenShift is vulnerable to local credential compromise. An attacker who gains local access
Overview
IBM Financial Transaction Manager (FTM) on RedHat OpenShift is vulnerable to local credential compromise. An attacker who gains local access can read sensitive data and execute unauthorized actions. The flaw stems from inadequate protection of stored credentials.
Description
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a local attacker to obtain sensitive information and perform unauthorized actions due to insufficiently protected credentials.
Impact
Confidentiality: attackers can read transaction data and credentials. Integrity: unauthorized actions can alter or delete transaction records. Availability: potential for denial of service if critical functions are tampered. Defenders: system administrators, security teams managing FTM deployments.
Remediation
Apply the vendor-supplied patch that encrypts stored credentials and enforces least-privilege access. Ensure that FTM pods run with non-root users and restrict local shell access. Regularly audit credential storage and enforce strong password policies. Monitor logs for anomalous credential usage.
Risk context
Severity is high with CVSS 8.8. No EPSS data available, but the vulnerability can be exploited by any local user, making it a significant risk for environments where local access is possible.
Affected products
- IBM Financial Transaction Manager
- IBM FTM RedHat OpenShift
Scores
- Severity
- high
- CVSS v2
- 6.8
- CVSS v3
- 8.8
- CVSS v4
- —
- EPSS
- —