Impact
IBM Financial Transaction Manager for RedHat OpenShift contains a buffer overflow that arises when the application does not validate a specified quantity field correctly. An attacker who is authenticated to the system can use the flaw to execute arbitrary code with the privileges of the affected service. The potential impact includes full compromise of confidentiality, integrity, and availability of the transaction manager and potentially the underlying infrastructure.
Affected Systems
The vulnerability affects IBM Financial Transaction Manager (FTM) for RedHat OpenShift versions up to 4.0.6.0. IBM has provided a remediation upgrade to version 4.0.11.0 via the VRMFRemediation / First Fix, which resolves the flaw. All deployments running the earlier releases are at risk until the upgrade is applied.
Risk and Exploitability
The CVSS score of 8.8 classifies this flaw as high severity, and while the EPSS score is currently not available, the absence of a KEV listing suggests no publicly known exploits yet. The attack vector is remote and requires an authenticated session; therefore, any user with valid credentials could potentially trigger the exploit. Given the high privilege gain, the risk to affected systems is significant and warrants urgent attention.
OpenCVE Enrichment