Impact
IBM Financial Transaction Manager (FTM) for RedHat OpenShift contains a flaw where credentials are stored without adequate protection, allowing a local attacker who can access the node running FTM to read those credentials and thereby obtain sensitive information. This weakness is classified as CWE‑522 and results in potential disclosure of privileged data. The CVSS score of 6.5 reflects moderate severity and indicates that the vulnerability requires local access rather than remote exploitation.
Affected Systems
The vulnerable product is IBM Financial Transaction Manager (FTM) for RedHat OpenShift. Versions before 4.0.11.0 – including the 4.0.6.0 release mentioned in the CPE – are impacted. The issue applies to deployments running on RedHat OpenShift platforms as described by IBM.
Risk and Exploitability
The CVSS score of 6.5 places the vulnerability in the medium range. EPSS data is not available, so the likelihood of exploitation cannot be quantified. The vulnerability is not listed in the CISA KEV catalog, indicating no confirmed active exploitation. Attackers must have local (or privileged) access to the FTM environment to exploit the flaw; remote exploitation is not possible.
OpenCVE Enrichment