Impact
IBM Financial Transaction Manager (FTM) for RedHat OpenShift contains an issue where credentials are not adequately protected, enabling a local attacker to read sensitive data and execute operations beyond intended permissions. The weakness falls under CWE‑522 (Insufficiently Protected Credentials) and can compromise both confidentiality and integrity of the transaction processing environment.
Affected Systems
The vulnerability applies to IBM Financial Transaction Manager (FTM) for RedHat OpenShift, specifically versions noted as 4.0.6.0 in the Common Platform Enumeration data and the vulnerability is resolved in FTM 4.0.11.0 for RedHat OpenShift.
Risk and Exploitability
With a CVSS score of 8.8 the severity is high. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. A likely attack path would involve a user who has local access to the FTM deployment, exploiting weak credential handling to gain additional privileges or read protected information. If left unpatched, this local attacker could manipulate transaction data or expose sensitive financial information.
OpenCVE Enrichment