Impact
IBM Financial Transaction Manager for RedHat OpenShift contains an improper authentication flaw that permits a remote attacker to exploit missing authorization controls and carry out unauthorized actions. The weakness is a classic authentication bypass, classified under CWE-287, enabling privileged or sensitive transactions that should otherwise be protected.
Affected Systems
The affected product is IBM Financial Transaction Manager (FTM) for RedHat OpenShift, specifically versions 4.0.6.0 and earlier. IBM recommends resolving the issue by upgrading to FTM 4.0.11.0, which has been released as the first fix for the vulnerability.
Risk and Exploitability
The CVSS score of 8.2 indicates a high impact. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, meaning there is no current data on exploitation prevalence. Attackers would likely target the FTM application remotely, using exposed services or APIs to trigger the authentication flaw and acquire unauthorized privileges, though no specific exploitation details are given in the advisory.
OpenCVE Enrichment