Description
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to execute arbitrary code due to improper validation of a specified quantity.
Published: 2026-09-22
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: Remote code execution
Action: Immediate Patch
AI Analysis

Impact

IBM Financial Transaction Manager for RedHat OpenShift contains a buffer overflow that arises when the application does not validate a specified quantity field correctly. An attacker who is authenticated to the system can use the flaw to execute arbitrary code with the privileges of the affected service. The potential impact includes full compromise of confidentiality, integrity, and availability of the transaction manager and potentially the underlying infrastructure.

Affected Systems

The vulnerability affects IBM Financial Transaction Manager (FTM) for RedHat OpenShift versions up to 4.0.6.0. IBM has provided a remediation upgrade to version 4.0.11.0 via the VRMFRemediation / First Fix, which resolves the flaw. All deployments running the earlier releases are at risk until the upgrade is applied.

Risk and Exploitability

The CVSS score of 8.8 classifies this flaw as high severity, and while the EPSS score is currently not available, the absence of a KEV listing suggests no publicly known exploits yet. The attack vector is remote and requires an authenticated session; therefore, any user with valid credentials could potentially trigger the exploit. Given the high privilege gain, the risk to affected systems is significant and warrants urgent attention.

Generated by OpenCVE AI on September 22, 2026 at 22:22 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerabilities now by updating FTM deployments to the following Affected Product(s)Resolved by VRMFRemediation / First FixFinancial Transaction Manager (FTM) for RedHat OpenShift4.0.11.0 FTM 4.0.11.0 https://www.ibm.com/support/pages/node/7285661


OpenCVE Recommended Actions

  • Apply the IBM VRMFRemediation or First Fix to upgrade to Financial Transaction Manager 4.0.11.0
  • Restrict access to the FTM service by enforcing strict authentication and role‑based authorization so only trusted users can invoke quantity‑related operations
  • Monitor authentication logs and unusual outbound traffic for signs of exploitation attempts

Generated by OpenCVE AI on September 22, 2026 at 22:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 21:45:00 +0000

Type Values Removed Values Added
Description IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to execute arbitrary code due to improper validation of a specified quantity.
Title IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities
First Time appeared Ibm
Ibm financial Transaction Manager Ftmfor Redhat Openshift
Weaknesses CWE-787
CPEs cpe:2.3:a:ibm:financial_transaction_manager_ftmfor_redhat_openshift:4.0.6.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm financial Transaction Manager Ftmfor Redhat Openshift
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Ibm Financial Transaction Manager Ftmfor Redhat Openshift
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-22T21:30:25.835Z

Reserved: 2026-07-27T21:31:02.879Z

Link: CVE-2026-17636

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-22T22:17:08.207

Modified: 2026-09-22T22:17:08.207

Link: CVE-2026-17636

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-22T22:30:05Z

Weaknesses