Impact
IBM Financial Transaction Manager for RedHat OpenShift could allow a remote attacker to execute arbitrary ESQL commands because the software does not properly neutralize special characters in an ESQL command. This injection flaw allows the attacker to run arbitrary database commands with the privileges of the system, potentially exposing or altering sensitive financial data. The weakness is a classic SQL‑injection style vulnerability (CWE‑89).
Affected Systems
The vulnerability affects IBM’s Financial Transaction Manager (FTM) for RedHat OpenShift, specifically the 4.0.6.0 release. The vendor recommends upgrading to FTM 4.0.11.0, which contains the fix.
Risk and Exploitability
The CVSS base score is 8.1, indicating a high severity. EPSS information is not available, and the flaw is not listed in the CISA KEV catalog. The attack vector is inferred to be remote exploitation where an attacker can submit a crafted ESQL payload to an exposed interface. Successful exploitation could lead to full compromise of the affected FTM instance.
OpenCVE Enrichment