Description
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote unauthenticated attacker to view and modify sensitive information and cause a denial of service due to improper authorization.
Published: 2026-09-22
Score: 7.3 High
EPSS: n/a
KEV: No
Impact: Remote unauthenticated access enabling data modification and denial of service
Action: Immediate Patch
AI Analysis

Impact

IBM Financial Transaction Manager (FTM) for RedHat OpenShift has an authorization flaw that allows a remote attacker who does not have valid credentials to view and tamper with sensitive data and to disrupt service availability. The vulnerability arises from improper authorization checks, which is categorized under CWE-862, and can lead to full compromise of the transaction processing system if exploited. The impact is significant because it affects financial transaction integrity and availability, critical to many enterprise operations.

Affected Systems

The affected product is IBM Financial Transaction Manager (FTM) for RedHat OpenShift. Vulnerable versions include 4.0.6.0 and earlier, according to the CPE entry. IBM recommends updating to the 4.0.11.0 release, which contains the fix.

Risk and Exploitability

The CVSS score of 7.3 classifies this vulnerability as high severity. EPSS data is not available, so the exploitation probability is unknown, but the lack of a requirement for authentication indicates that an attacker could launch a remote attack from anywhere. The vulnerability is not currently listed in the CISA KEV catalog, reducing immediate awareness among organizations that rely on that database. However, the high CVSS and remote nature of the flaw make it a priority to remediate before exploitation is observed.

Generated by OpenCVE AI on September 22, 2026 at 22:24 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerabilities now by updating FTM deployments to the following Affected Product(s)Resolved by VRMFRemediation / First FixFinancial Transaction Manager (FTM) for RedHat OpenShift4.0.11.0 FTM 4.0.11.0 https://www.ibm.com/support/pages/node/7285661


OpenCVE Recommended Actions

  • Apply the IBM patch to upgrade FTM to version 4.0.11.0 or later following the guidance on the IBM support site
  • Apply the vendor‑issued VRMFRemediation procedure as documented in the IBM support article for FTM 4.0.11.0
  • Restrict external access to the FTM deployment, for example by firewalling or placing the service behind a VPN, until the patch is applied
  • Monitor system logs for unexpected read or write activity to the transaction manager

Generated by OpenCVE AI on September 22, 2026 at 22:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 21:45:00 +0000

Type Values Removed Values Added
Description IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote unauthenticated attacker to view and modify sensitive information and cause a denial of service due to improper authorization.
Title IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities
First Time appeared Ibm
Ibm financial Transaction Manager Ftmfor Redhat Openshift
Weaknesses CWE-862
CPEs cpe:2.3:a:ibm:financial_transaction_manager_ftmfor_redhat_openshift:4.0.6.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm financial Transaction Manager Ftmfor Redhat Openshift
References
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'}


Subscriptions

Ibm Financial Transaction Manager Ftmfor Redhat Openshift
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-22T21:27:46.316Z

Reserved: 2026-07-27T20:26:49.744Z

Link: CVE-2026-17618

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-22T22:17:07.817

Modified: 2026-09-22T22:17:07.817

Link: CVE-2026-17618

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-22T22:30:05Z

Weaknesses