Impact
IBM Financial Transaction Manager for RedHat OpenShift can transmit sensitive transaction data in cleartext, allowing a remote attacker to intercept and read confidential information. The vulnerability is a cleartext transmission flaw, classified as an information disclosure issue. It is not explicitly stated whether authentication is required; this is inferred. An attacker could potentially capture account details, transaction amounts, or other protected data, which may lead to financial loss or regulatory non-compliance.
Affected Systems
The affected product is IBM Financial Transaction Manager (FTM) for RedHat OpenShift, specifically versions starting with 4.0.6.0. The vendor’s advisory states that updating to the 4.0.11.0 release resolves the issue.
Risk and Exploitability
The CVSS score is 7.5, indicating high severity. The EPSS score is not available, so the exact likelihood of exploitation is unclear. The description implies the vulnerability involves cleartext transmission, which could be reachable over the network, but the specific access conditions are not detailed in the advisory. The vulnerability is not listed in the CISA KEV catalog, yet it remains a significant risk because an attacker can collect sensitive data by observing network traffic.
OpenCVE Enrichment