rootpwn

medium · CVSS v3 6.2

CVE-2026-19267

IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to missing authentication on the Business Rul…

Description

IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to missing authentication on the Business Rules Manager commands REST endpoint (`CommandsResource.java:31`). A local actor can invoke unauthenticated commands to cause resource exhaustionand halt business-rule management functions.

Scores

Severity
medium
CVSS v2
4.9
CVSS v3
6.2
CVSS v4
EPSS

← All CVEs