Impact
The vulnerability is a server‑side request forgery (SSRF) in IBM Financial Transaction Manager for RedHat OpenShift. A local attacker who can send requests to the FTM application can cause the service to issue requests to internal endpoints, allowing the attacker to read sensitive data or perform actions that are normally restricted within the cluster. The weakness is categorized as CWE‑918.
Affected Systems
IBM Financial Transaction Manager (FTM) for RedHat OpenShift versions 4.0.6.0 and earlier are affected. The issue is fixed in FTM 4.0.11.0, which includes the recommended update.
Risk and Exploitability
The CVSS score of 7.9 indicates a high‑severity flaw. The EPSS score is unavailable, and the vulnerability is not listed in the CISA KEV catalog, so no public exploitation has been reported. However, because the flaw can be triggered by a local attacker interacting with the FTM service, systems that expose the application to users with any local privileges could be at risk of unintended data exposure or actions. Administrators should treat the issue as high risk and remediate promptly.
OpenCVE Enrichment