Description
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a local attacker to gain unauthorized access to sensitive information and modify transaction data due to the use of hard-coded credentials.
Published: 2026-09-22
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: Unauthorized access to sensitive data and potential modification of transaction records
Action: Apply Patch
AI Analysis

Impact

The vulnerability is caused by hard‑coded credentials embedded in IBM Financial Transaction Manager (FTM) for RedHat OpenShift. An attacker who can gain local access to a host running FTM can use those credentials to log in as a privileged user, thereby viewing confidential information and altering transaction data. The weakness is a credential disclosure flaw, classified as CWE‑798.

Affected Systems

The affected product is IBM Financial Transaction Manager (FTM) for RedHat OpenShift, specifically version 4.0.6.0 and earlier. IBM recommends updating to FTM 4.0.11.0, which resolves the issue. The product is deployed in RedHat OpenShift 4 environments.

Risk and Exploitability

The vulnerability scores a CVSS of 8.8, indicating a high severity. Since the EPSS score is not available, the exploit probability is uncertain, but the absence of a KEV listing suggests it is not currently a known, actively exploited vulnerability. However, local attackers with foothold on a cluster node could exploit it; therefore the loss of confidentiality, integrity, and overall system availability is significant. The likely attack vector is local, requiring attacker presence on a node or the ability to execute code on the host on which FTM runs.

Generated by OpenCVE AI on September 22, 2026 at 22:20 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerabilities now by updating FTM deployments to the following Affected Product(s)Resolved by VRMFRemediation / First FixFinancial Transaction Manager (FTM) for RedHat OpenShift4.0.11.0 FTM 4.0.11.0 https://www.ibm.com/support/pages/node/7285661


OpenCVE Recommended Actions

  • Deploy the IBM FTM 4.0.11.0 fix for RedHat OpenShift immediately
  • Disable or remove any hard‑coded credentials in the configuration or code base per IBM’s guidance
  • Restrict local host access and enforce least privilege so that only trusted administrative staff can run FTM components

Generated by OpenCVE AI on September 22, 2026 at 22:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 21:45:00 +0000

Type Values Removed Values Added
Description IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a local attacker to gain unauthorized access to sensitive information and modify transaction data due to the use of hard-coded credentials.
Title IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities
First Time appeared Ibm
Ibm financial Transaction Manager Ftmfor Redhat Openshift
Weaknesses CWE-798
CPEs cpe:2.3:a:ibm:financial_transaction_manager_ftmfor_redhat_openshift:4.0.6.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm financial Transaction Manager Ftmfor Redhat Openshift
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Ibm Financial Transaction Manager Ftmfor Redhat Openshift
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-22T21:37:11.866Z

Reserved: 2026-07-27T21:58:00.684Z

Link: CVE-2026-17644

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-22T22:17:08.597

Modified: 2026-09-22T22:17:08.597

Link: CVE-2026-17644

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-22T22:30:05Z

Weaknesses
  • CWE-798

    Use of Hard-coded Credentials