Impact
IBM Financial Transaction Manager (FTM) for RedHat OpenShift has an authorization flaw that allows a remote attacker who does not have valid credentials to view and tamper with sensitive data and to disrupt service availability. The vulnerability arises from improper authorization checks, which is categorized under CWE-862, and can lead to full compromise of the transaction processing system if exploited. The impact is significant because it affects financial transaction integrity and availability, critical to many enterprise operations.
Affected Systems
The affected product is IBM Financial Transaction Manager (FTM) for RedHat OpenShift. Vulnerable versions include 4.0.6.0 and earlier, according to the CPE entry. IBM recommends updating to the 4.0.11.0 release, which contains the fix.
Risk and Exploitability
The CVSS score of 7.3 classifies this vulnerability as high severity. EPSS data is not available, so the exploitation probability is unknown, but the lack of a requirement for authentication indicates that an attacker could launch a remote attack from anywhere. The vulnerability is not currently listed in the CISA KEV catalog, reducing immediate awareness among organizations that rely on that database. However, the high CVSS and remote nature of the flaw make it a priority to remediate before exploitation is observed.
OpenCVE Enrichment