rootpwn

high · CVSS v3 7.6

CVE-2026-18123

IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to a denial‑of‑service attack due to improper use of reflection w

Overview

IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to a denial‑of‑service attack due to improper use of reflection with externally controlled input. A remote attacker can crash the application, disrupting financial transaction processing. This flaw can affect the availability of critical financial services.

Description

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to cause a denial of service due to the improper use of reflection with externally controlled input.

Impact

The vulnerability can cause a denial of service, disrupting the availability of the transaction processing system. While confidentiality and integrity are not directly compromised, repeated crashes may expose sensitive logs or create windows for other attacks. The impact is primarily on the availability of the financial transaction services. Defenders should treat this as a high‑priority availability issue.

Remediation

Apply the latest IBM FTM patch that fixes the reflection handling. If a patch is not yet available, restrict external input to validated, whitelisted values and enforce strict input validation. Additionally, enable application‑level health checks and configure Kubernetes readiness probes to restart the pod automatically. Monitor logs for reflection errors and block suspicious requests at the API gateway.

Risk context

Severity is high with CVSS 7.6. No EPSS data available. The vulnerability poses a significant availability risk to financial transaction systems, warranting prompt patching or mitigation.

Affected products

  • IBM FTM RedHat OpenShift

Scores

Severity
high
CVSS v2
7.3
CVSS v3
7.6
CVSS v4
EPSS

denial-of-service reflection IBM FTM OpenShift availability high-severity

← All CVEs