Impact
IBM Financial Transaction Manager (FTM) for RedHat OpenShift contains a flaw where XML external entity references are not properly restricted. An attacker who can authenticate to the service can craft a malicious XML payload that, when parsed, resolves unauthorized external entities, allowing the attacker to read system files, environment variables or other internal data. This leads to the disclosure of sensitive information.
Affected Systems
This flaw impacts IBM Financial Transaction Manager (FTM) for RedHat OpenShift, specifically the 4.0.6.0 release and older versions. IBM recommends applying the remediation release FTM 4.0.11.0 to all OpenShift deployments to eliminate the vulnerability.
Risk and Exploitability
The CVSS v3 score of 8.5 classifies the issue as High severity. No EPSS score is available, making the exploitation probability currently unknown. The flaw is not listed in the CISA KEV catalog. Exploitation requires an authenticated attacker with the ability to submit crafted XML payloads to the service; the remote XML parser lacks safeguards against external entity resolution. Given the authenticated remote attack vector and high severity, the risk is significant for environments where FTM is exposed to internal users.
OpenCVE Enrichment