Impact
IBM Financial Transaction Manager for RedHat OpenShift contains a misconfiguration in its HTTP method-based security constraints that permits an unauthenticated remote attacker to invoke privileged API calls. The flaw bypasses authentication checks for certain HTTP methods, enabling attackers to manipulate or retrieve transaction data without credentials. With a CVSS score of 9.1 the impact is high, potentially compromising the confidentiality, integrity, and availability of financial transactions.
Affected Systems
The affected component is IBM Financial Transaction Manager for RedHat OpenShift. Versions 4.0.6.0 and earlier are impacted. IBM recommends updating to version 4.0.11.0, which includes the necessary fix.
Risk and Exploitability
Because the vulnerability does not require authentication, an attacker only needs network connectivity to the OpenShift cluster’s FTM endpoint to send malicious HTTP requests. The EPSS score is not available, but the high CVSS and lack of authentication requirements translate into a high likelihood of exploitation. Though it is not listed in the CISA KEV catalog, the vulnerability’s severity warrants immediate remediation.
OpenCVE Enrichment