Description
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to read arbitrary files due to improper path canonicalization.
Published: 2026-09-22
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: Remote File Read via Improper Path Canonicalization
Action: Patch Deployment
AI Analysis

Impact

IBM Financial Transaction Manager (FTM) for RedHat OpenShift contains an improper path canonicalization flaw that can let an attacker read arbitrary files. The vulnerability allows the attacker to supply a crafted path that bypasses normal checks, enabling the disclosure of any file accessible to the FTM process. The impact is a compromise of confidentiality with potential exposure of sensitive configuration or system data. The weakness is classified as a path traversal issue (CWE-22).

Affected Systems

The problem affects IBM Financial Transaction Manager (FTM) for RedHat OpenShift versions prior to 4.0.11.0, including the 4.0.6.0 release cited in the CPE. IBM has confirmed that the first fix is available in FTM 4.0.11.0 and recommends all deployments upgrade to this version to eliminate the flaw.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity, and while the EPSS score is not available, the vulnerability is not listed in CISA’s KEV catalog, suggesting current exploitation activity is either low or not documented. The likely attack vector is remote, inferred from the nature of the flaw and the fact that a web‑based or API‑based interface could be used to supply the malicious path. An attacker would need network access to the FTM service and could trigger the vulnerability by sending a crafted request that includes a path designed to traverse and exceed directory boundaries.

Generated by OpenCVE AI on September 22, 2026 at 23:28 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerabilities now by updating FTM deployments to the following Affected Product(s)Resolved by VRMFRemediation / First FixFinancial Transaction Manager (FTM) for RedHat OpenShift4.0.11.0 FTM 4.0.11.0 https://www.ibm.com/support/pages/node/7285661


OpenCVE Recommended Actions

  • Upgrade IBM Financial Transaction Manager to version 4.0.11.0 or later. This is the officially recommended fix from IBM.
  • Reconfigure the application or underlying server to enforce strict directory restrictions, ensuring that only authorized system directories are readable by the FTM process. This mitigates path traversal by limiting the scope of exposed files.
  • Implement file‑access monitoring and alerting for abnormal read requests, so that any attempt to exploit the canonicalization flaw can be detected early.

Generated by OpenCVE AI on September 22, 2026 at 23:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to read arbitrary files due to improper path canonicalization.
Title IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities
First Time appeared Ibm
Ibm financial Transaction Manager Ftmfor Redhat Openshift
Weaknesses CWE-22
CPEs cpe:2.3:a:ibm:financial_transaction_manager_ftmfor_redhat_openshift:4.0.6.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm financial Transaction Manager Ftmfor Redhat Openshift
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Ibm Financial Transaction Manager Ftmfor Redhat Openshift
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-22T21:46:17.767Z

Reserved: 2026-07-28T18:01:57.894Z

Link: CVE-2026-18114

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-22T22:17:09.520

Modified: 2026-09-22T22:17:09.520

Link: CVE-2026-18114

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-23T01:00:10Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')