Impact
The vulnerability allows a remote authenticated attacker to gain elevated privileges in IBM Financial Transaction Manager (FTM) for RedHat OpenShift because the application fails to enforce proper privilege boundaries. This flaw permits the attacker to execute actions with higher authority than the intended user role, effectively compromising the integrity of financial transactions. The weakness is categorized as improper privilege management, mapped to CWE-269.
Affected Systems
Affected systems are IBM's Financial Transaction Manager (FTM) deployed on RedHat OpenShift. Versions affected include the 4.0.6.0 release and earlier, as indicated by the system IDs and the CVE reference list. IBM recommends updating to the 4.0.11.0 release to resolve the issue.
Risk and Exploitability
The CVSS score of 9.1 classifies the vulnerability as Critical. Since the EPSS score is not available, the likelihood of exploitation is uncertain but given the high severity and remote authenticated nature, it warrants immediate attention. The vulnerability is not listed in CISA KEV. An attacker would need valid authentication credentials to exploit the flaw; the remote nature of the bug suggests the attack would likely occur over internal or external interfaces that provide authenticated access. The vulnerability relies on improper privilege checks, so any secret or administrative privilege exposed to the attacker enables the elevation.
OpenCVE Enrichment