Impact
IBM Financial Transaction Manager (FTM) for RedHat OpenShift contains an improper path canonicalization flaw that can let an attacker read arbitrary files. The vulnerability allows the attacker to supply a crafted path that bypasses normal checks, enabling the disclosure of any file accessible to the FTM process. The impact is a compromise of confidentiality with potential exposure of sensitive configuration or system data. The weakness is classified as a path traversal issue (CWE-22).
Affected Systems
The problem affects IBM Financial Transaction Manager (FTM) for RedHat OpenShift versions prior to 4.0.11.0, including the 4.0.6.0 release cited in the CPE. IBM has confirmed that the first fix is available in FTM 4.0.11.0 and recommends all deployments upgrade to this version to eliminate the flaw.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, and while the EPSS score is not available, the vulnerability is not listed in CISA’s KEV catalog, suggesting current exploitation activity is either low or not documented. The likely attack vector is remote, inferred from the nature of the flaw and the fact that a web‑based or API‑based interface could be used to supply the malicious path. An attacker would need network access to the FTM service and could trigger the vulnerability by sending a crafted request that includes a path designed to traverse and exceed directory boundaries.
OpenCVE Enrichment