rootpwn

high · CVSS v3 8.2

CVE-2026-18074

IBM Financial Transaction Manager (FTM) for RedHat OpenShift has a high severity flaw that allows remote attackers to bypass authentication

Overview

IBM Financial Transaction Manager (FTM) for RedHat OpenShift has a high severity flaw that allows remote attackers to bypass authentication and perform unauthorized actions. The vulnerability stems from improper authentication and missing authorization controls. It can be exploited without user interaction, potentially compromising financial transaction processing.

Description

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to perform unauthorized actions due to improper authentication and missing authorization.

Impact

Confidentiality: attackers can read or modify transaction data. Integrity: unauthorized transaction creation or alteration. Availability: potential for denial of service by flooding the system. Defenders: system administrators, security teams managing IBM FTM deployments.

Remediation

Apply the latest IBM FTM security patch or update to the latest version. Verify that authentication mechanisms are enabled and properly configured. Enforce role-based access control and least privilege. Restrict network access to FTM services to trusted IP ranges and monitor for anomalous activity.

Risk context

Severity is high with a CVSS v3 score of 8.2. No EPSS data available. The vulnerability can be exploited remotely, so timely patching is critical.

Affected products

  • IBM Financial Transaction Manager
  • IBM FTM for RedHat OpenShift

Scores

Severity
high
CVSS v2
8.5
CVSS v3
8.2
CVSS v4
EPSS

IBM FTM RedHat OpenShift authentication authorization high severity remote exploitation

← All CVEs