Description
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to obtain sensitive information due to improper restriction of XML external entity references.
Published: 2026-09-22
Score: 8.5 High
EPSS: n/a
KEV: No
Impact: Sensitive Information Disclosure
Action: Patch Immediately
AI Analysis

Impact

IBM Financial Transaction Manager (FTM) for RedHat OpenShift contains a flaw where XML external entity references are not properly restricted. An attacker who can authenticate to the service can craft a malicious XML payload that, when parsed, resolves unauthorized external entities, allowing the attacker to read system files, environment variables or other internal data. This leads to the disclosure of sensitive information.

Affected Systems

This flaw impacts IBM Financial Transaction Manager (FTM) for RedHat OpenShift, specifically the 4.0.6.0 release and older versions. IBM recommends applying the remediation release FTM 4.0.11.0 to all OpenShift deployments to eliminate the vulnerability.

Risk and Exploitability

The CVSS v3 score of 8.5 classifies the issue as High severity. No EPSS score is available, making the exploitation probability currently unknown. The flaw is not listed in the CISA KEV catalog. Exploitation requires an authenticated attacker with the ability to submit crafted XML payloads to the service; the remote XML parser lacks safeguards against external entity resolution. Given the authenticated remote attack vector and high severity, the risk is significant for environments where FTM is exposed to internal users.

Generated by OpenCVE AI on September 22, 2026 at 23:54 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerabilities now by updating FTM deployments to the following Affected Product(s)Resolved by VRMFRemediation / First FixFinancial Transaction Manager (FTM) for RedHat OpenShift4.0.11.0 FTM 4.0.11.0 https://www.ibm.com/support/pages/node/7285661


OpenCVE Recommended Actions

  • Apply the IBM‑provided patch (FTM 4.0.11.0) to all OpenShift deployments of Financial Transaction Manager.
  • Configure the XML parser within FTM to disallow external entity references or enable a safe parsing mode.
  • Enable logging of XML parsing errors or unexpected entity expansion and monitor for potential exploitation attempts.

Generated by OpenCVE AI on September 22, 2026 at 23:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to obtain sensitive information due to improper restriction of XML external entity references.
Title IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities
First Time appeared Ibm
Ibm financial Transaction Manager Ftmfor Redhat Openshift
Weaknesses CWE-611
CPEs cpe:2.3:a:ibm:financial_transaction_manager_ftmfor_redhat_openshift:4.0.6.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm financial Transaction Manager Ftmfor Redhat Openshift
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N'}


Subscriptions

Ibm Financial Transaction Manager Ftmfor Redhat Openshift
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-22T21:42:56.951Z

Reserved: 2026-07-27T22:02:14.543Z

Link: CVE-2026-17646

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-22T22:17:08.860

Modified: 2026-09-22T22:17:08.860

Link: CVE-2026-17646

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-23T00:00:09Z

Weaknesses
  • CWE-611

    Improper Restriction of XML External Entity Reference