Impact
IBM Financial Transaction Manager for RedHat OpenShift transmits sensitive or security‑critical data over a network channel without encryption, allowing an unauthorized actor able to sniff traffic to capture that data. The weakness (CWE‑523) is a lack of confidentiality protection for data in transit, meaning the system can inadvertently disclose transaction information that may be confidential or security‑critical. No evidence in the CVE description suggests that the attacker could modify data or cause denial of service; the impact is limited to information disclosure.
Affected Systems
The vulnerability affects IBM Financial Transaction Manager (FTM) for RedHat OpenShift versions 4.0.6.0 through 4.0.10.0. The vendor recommends upgrading to version 4.0.11.0 or later to remove the flaw. The affected CPE string listed is cpe:2.3:a:ibm:financial_transaction_manager_ftmfor_redhat_openshift:4.0.6.0:*:*:*:*:*:*:*, indicating that the specific affected release was 4.0.6.0 and subsequent patch levels up to 4.0.10.0 are also vulnerable.
Risk and Exploitability
The CVSS score is 5.3, which indicates moderate severity. The EPSS score is not available, so the current exploitation probability is not quantified. Because the vulnerability is based on transmitting cleartext data, an attacker with access to network traffic within the cluster can easily capture the data using standard packet‑sniffing tools. The risk exists when the data plane is exposed to network segments that are not trusted or are outside the organization’s secure perimeter. The vulnerability is not listed in the CISA KEV catalog, but IBM’s official fix addresses the flaw.
OpenCVE Enrichment