Impact
The vulnerability in IBM Financial Transaction Manager arises from hard‑coded cryptographic keys and initialization vectors. An authenticated attacker can obtain sensitive transaction data and forge authentication tags that the system trusts, enabling data disclosure and unauthorized access. The weakness is classified as CWE‑327.
Affected Systems
The affected product is IBM Financial Transaction Manager (FTM) for RedHat OpenShift. Versions prior to the 4.0.11.0 fix, such as 4.0.6.0, are vulnerable. Updates to 4.0.11.0 or later address the issue.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity. EPSS data is unavailable, and the vulnerability is not listed in the CISA KEV catalog. The attack likely requires remote authenticated access; once an attacker has valid credentials, the hard-coded keys simplify extraction of confidential data and creation of legitimate‑looking authentication tokens. While the impact is moderate, the ability to tamper with auth mechanisms makes remediation urgent.
OpenCVE Enrichment