high · CVSS v3 8.5
CVE-2026-17646
IBM Financial Transaction Manager (FTM) for RedHat OpenShift has a vulnerability that allows a remote authenticated attacker to read sensiti
Overview
IBM Financial Transaction Manager (FTM) for RedHat OpenShift has a vulnerability that allows a remote authenticated attacker to read sensitive data. The flaw arises from improper restriction of XML external entity references. This can expose confidential transaction information.
Description
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to obtain sensitive information due to improper restriction of XML external entity references.
Impact
Confidentiality: Sensitive transaction data may be disclosed to authenticated attackers. Integrity: XML parsing may be manipulated. Availability: Not directly impacted. Defenders: System administrators and security teams must monitor for unauthorized XML entity usage.
Remediation
Apply IBM FTM patch that disables external entity processing or configure the XML parser to disallow external entities. Ensure only trusted users have access to FTM. Use network segmentation and monitor for anomalous XML traffic.
Risk context
High severity (CVSS 8.5). No EPSS data available. Immediate attention recommended.
Affected products
- IBM FTM
- RedHat OpenShift
Scores
- Severity
- high
- CVSS v2
- 7.5
- CVSS v3
- 8.5
- CVSS v4
- —
- EPSS
- —