Impact
The vulnerability is caused by hard‑coded credentials embedded in IBM Financial Transaction Manager (FTM) for RedHat OpenShift. An attacker who can gain local access to a host running FTM can use those credentials to log in as a privileged user, thereby viewing confidential information and altering transaction data. The weakness is a credential disclosure flaw, classified as CWE‑798.
Affected Systems
The affected product is IBM Financial Transaction Manager (FTM) for RedHat OpenShift, specifically version 4.0.6.0 and earlier. IBM recommends updating to FTM 4.0.11.0, which resolves the issue. The product is deployed in RedHat OpenShift 4 environments.
Risk and Exploitability
The vulnerability scores a CVSS of 8.8, indicating a high severity. Since the EPSS score is not available, the exploit probability is uncertain, but the absence of a KEV listing suggests it is not currently a known, actively exploited vulnerability. However, local attackers with foothold on a cluster node could exploit it; therefore the loss of confidentiality, integrity, and overall system availability is significant. The likely attack vector is local, requiring attacker presence on a node or the ability to execute code on the host on which FTM runs.
OpenCVE Enrichment