Impact
The vulnerability arises from IBM Financial Transaction Manager’s use of reflection with externally controlled input, enabling a remote attacker to trigger a denial of service. This misuse of reflection allows untrusted data to be processed in a way that can disrupt the FTM service. The weakness is identified as CWE-470, indicating that untrusted input is used to drive dynamic execution.
Affected Systems
IBM Financial Transaction Manager for RedHat OpenShift is the affected product. Deployments running any version prior to 4.0.11.0, including the 4.0.6.0 release indicated in the CPE, are vulnerable. The recommended fix is to upgrade the product to FTM 4.0.11.0 or later.
Risk and Exploitability
The CVSS score of 7.6 signals high severity; the EPSS score is not available, so the current exploitation probability is uncertain. The vulnerability is not listed in the CISA KEV catalog. A remote attacker can send crafted input that the reflection mechanism will process, resulting in a denial of service and impacting the availability of the FTM application.
OpenCVE Enrichment