rootpwn

high · CVSS v3 8.8

CVE-2026-17644

IBM Financial Transaction Manager (FTM) for RedHat OpenShift contains hard-coded credentials that enable a local attacker to read and alter

Overview

IBM Financial Transaction Manager (FTM) for RedHat OpenShift contains hard-coded credentials that enable a local attacker to read and alter transaction data. The flaw can be exploited without network access, making it a critical risk for on-prem or cloud deployments. Prompt remediation is essential to protect financial records.

Description

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a local attacker to gain unauthorized access to sensitive information and modify transaction data due to the use of hard-coded credentials.

Impact

Confidentiality: unauthorized disclosure of transaction details. Integrity: attacker can modify transaction records. Availability: potential disruption of transaction processing. Defenders: system administrators, security teams managing IBM FTM deployments.

Remediation

Apply the latest IBM FTM patch that removes hard-coded credentials. If a patch is unavailable, disable the default credentials and enforce strong, unique passwords. Reconfigure the application to use secure credential storage (e.g., HashiCorp Vault or Kubernetes secrets). Verify that the OpenShift cluster is updated to the latest security baseline.

Risk context

Severity is high with CVSS 8.8. No EPSS data, but the local nature of the flaw means any compromised host can exploit it. Defenders should treat this as a high-priority issue.

Affected products

  • IBM FTM for RedHat OpenShift

Scores

Severity
high
CVSS v2
6.8
CVSS v3
8.8
CVSS v4
EPSS

hard-coded credentials local privilege escalation IBM FTM RedHat OpenShift confidentiality integrity patch

← All CVEs