high · CVSS v3 8.8
CVE-2026-17644
IBM Financial Transaction Manager (FTM) for RedHat OpenShift contains hard-coded credentials that enable a local attacker to read and alter
Overview
IBM Financial Transaction Manager (FTM) for RedHat OpenShift contains hard-coded credentials that enable a local attacker to read and alter transaction data. The flaw can be exploited without network access, making it a critical risk for on-prem or cloud deployments. Prompt remediation is essential to protect financial records.
Description
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a local attacker to gain unauthorized access to sensitive information and modify transaction data due to the use of hard-coded credentials.
Impact
Confidentiality: unauthorized disclosure of transaction details. Integrity: attacker can modify transaction records. Availability: potential disruption of transaction processing. Defenders: system administrators, security teams managing IBM FTM deployments.
Remediation
Apply the latest IBM FTM patch that removes hard-coded credentials. If a patch is unavailable, disable the default credentials and enforce strong, unique passwords. Reconfigure the application to use secure credential storage (e.g., HashiCorp Vault or Kubernetes secrets). Verify that the OpenShift cluster is updated to the latest security baseline.
Risk context
Severity is high with CVSS 8.8. No EPSS data, but the local nature of the flaw means any compromised host can exploit it. Defenders should treat this as a high-priority issue.
Affected products
- IBM FTM for RedHat OpenShift
Scores
- Severity
- high
- CVSS v2
- 6.8
- CVSS v3
- 8.8
- CVSS v4
- —
- EPSS
- —