Impact
IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to a path traversal flaw that allows a remote authenticated attacker to modify arbitrary server files. By supplying a crafted path that bypasses directory boundaries, the attacker can write to files outside the intended directory, potentially compromising application integrity or enabling the upload of malicious files.
Affected Systems
IBM Financial Transaction Manager (FTM) for RedHat OpenShift, version 4.0.6.0 and earlier, is affected. The vendor’s remediation is available in the first‑fix release, which ships as version 4.0.11.0. Updating to that release resolves the path traversal issue.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity. Because the EPSS score is not available, there is currently no estimate of likelihood of exploitation. The vulnerability is not listed in the United States Cybersecurity and Infrastructure Security Agency KEV catalog, suggesting that no widespread active exploitation has been observed. An attacker would need valid authentication to the FTM instance and could then traverse directory paths to overwrite files, potentially impacting confidentiality, integrity, or availability.
OpenCVE Enrichment