Impact
IBM Financial Transaction Manager for RedHat OpenShift contains a flaw where the application uses functionality from an untrusted control sphere, allowing a local attacker to execute arbitrary commands. The vulnerability directly compromises the integrity and confidentiality of the transaction data processed by FTM and can be leveraged to gain elevated privileges within the cluster or to exfiltrate sensitive financial information. It is classified as CWE-829, which relates to the use of untrusted code or configuration sources.
Affected Systems
The issue affects IBM Financial Transaction Manager (FTM) for RedHat OpenShift 4.0.6.0 and earlier deployments. IBM has identified the patched release as FTM 4.0.11.0, which resolves the problem across all supported OpenShift versions. Any deployment that has not yet been upgraded to this version is considered vulnerable.
Risk and Exploitability
The CVSS base score of 8.8 categorizes the vulnerability as High severity. The EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog. There is no documented remote exploitation or network attack vector; the flaw requires a local attacker who can influence the control sphere and inject malicious input. Therefore, the likelihood of exploitation in a typical environment depends on the degree of access that potential attackers have to the FTM runtime.
OpenCVE Enrichment