Impact
IBM Financial Transaction Manager (FTM) for RedHat OpenShift contains an improper neutralization of HTML input that allows a remote attacker to inject arbitrary JavaScript into an authenticated user’s browser. The injected script executes in the context of the user’s authenticated session, enabling an attacker to steal session cookies, deface the page, or perform any action that the legitimate user can do, potentially leading to data compromise or credential theft. This is a classic reflected cross‑site scripting weakness (CWE-79).
Affected Systems
The vulnerability exists in IBM Financial Transaction Manager version 4.0.6.0 and earlier for RedHat OpenShift. IBM recommends upgrading to version 4.0.11.0, the first release that contains the required remediation. The affected product is the FTM component deployed within OpenShift clusters as described by the vendor.
Risk and Exploitability
The CVSS score of 8.2 classifies the problem as high severity. While no EPSS score is available, the lack of inclusion in the KEV catalog does not diminish the risk, as XSS can be exploited when a user opens a crafted page or submits malicious payloads. The attack vector likely requires the attacker to have a route to the victim’s browser, such as via phishing or an attacker‑controlled web page that the user visits while authenticated to FTM. Once the script runs, it can hijack the authenticated session or manipulate the user interface. The vulnerability’s impact hinges on the attacker’s ability to trick a user into loading the malicious code, but the potential damage is significant due to the elevated privileges carried by an authenticated session.
OpenCVE Enrichment