high · CVSS v3 7.9
CVE-2026-18066
IBM Financial Transaction Manager (FTM) on RedHat OpenShift is vulnerable to server‑side request forgery, allowing a local attacker to read
Overview
IBM Financial Transaction Manager (FTM) on RedHat OpenShift is vulnerable to server‑side request forgery, allowing a local attacker to read sensitive data and trigger unauthorized actions. The flaw can be exploited by any user with local access to the FTM container. It is critical for organizations running FTM to address this promptly.
Description
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a local attacker to obtain sensitive information and trigger unauthorized actions due to server-side request forgery.
Impact
Confidentiality: attacker can read transaction data and internal configuration. Integrity: attacker can trigger unauthorized transaction processing. Availability: potential for resource exhaustion if abused. Defenders: system administrators, security teams, and compliance officers.
Remediation
Apply the vendor‑supplied patch or update to the latest FTM release that fixes the SSRF flaw. If patch unavailable, restrict network access to the FTM service, enforce strict inbound/outbound firewall rules, and enable OpenShift security contexts to limit container privileges. Monitor logs for suspicious outbound requests and consider disabling unused APIs.
Risk context
Severity is high (CVSS 7.9) with no EPSS data; the vulnerability remains relevant for any environment running IBM FTM on OpenShift. Defenders should treat it as a high‑priority issue.
Affected products
- IBM FTM
- IBM Financial Transaction Manager
- RedHat OpenShift
- IBM FTM OpenShift
Scores
- Severity
- high
- CVSS v2
- 5.9
- CVSS v3
- 7.9
- CVSS v4
- —
- EPSS
- —