Impact
The vulnerability is a deserialization flaw that allows an attacker to execute arbitrary code when the FTM system processes untrusted data. If exploited, the attacker can compromise confidentiality, integrity, and availability of the FTM deployment, potentially gaining full control over the application and the underlying host.
Affected Systems
IBM Financial Transaction Manager for RedHat OpenShift 4.0.6.0 and earlier versions are affected. The issue is resolved in version 4.0.11.0, which should be deployed wherever possible.
Risk and Exploitability
The CVSS score of 8.8 classifies this flaw as high severity. While EPSS data is not available, the vulnerability can be exploited by an adjacent-network attacker who can deliver malicious data to the FTM instance, leading to full code execution. The flaw is not currently listed in CISA KEV, but the high severity and the ability to execute arbitrary code make it a priority for remediation.
OpenCVE Enrichment