Impact
IBM Financial Transaction Manager for RedHat OpenShift cannot properly validate cryptographic signatures, allowing a remote attacker to create and send messages that appear to be signed by a trusted source. This flaw lets an adversary inject fraudulent transaction requests or modify existing requests without detection, directly compromising the integrity and authenticity of financial workflows.
Affected Systems
The vulnerability affects IBM Financial Transaction Manager (FTM) deployments on RedHat OpenShift, specifically versions earlier than 4.0.11.0, including 4.0.6.0 and the listed CPE phantom. Users are advised to upgrade to 4.0.11.0, which resolves the signature validation issue.
Risk and Exploitability
The CVSS score of 7.4 indicates a high risk level, and while the EPSS score is not currently available, the attacker can likely exploit this flaw remotely without needing local privileges. The vulnerability is not yet reported in the CISA KEV catalog, but its nature could facilitate large‑scale financial fraud if left unpatched. A remote attacker can forge signed messages from any network location that can reach the FTM instance, making the attack vector primarily network‑based and easily reachable if the service is exposed.
OpenCVE Enrichment