Description
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to obtain sensitive information and forge authentication tags due to the use of hard-coded cryptographic keys and initialization vectors.
Published: 2026-09-22
Score: 5.4 Medium
EPSS: n/a
KEV: No
Impact: Remote Data Disclosure and Authentication Forgery
Action: Patch Now
AI Analysis

Impact

The vulnerability in IBM Financial Transaction Manager arises from hard‑coded cryptographic keys and initialization vectors. An authenticated attacker can obtain sensitive transaction data and forge authentication tags that the system trusts, enabling data disclosure and unauthorized access. The weakness is classified as CWE‑327.

Affected Systems

The affected product is IBM Financial Transaction Manager (FTM) for RedHat OpenShift. Versions prior to the 4.0.11.0 fix, such as 4.0.6.0, are vulnerable. Updates to 4.0.11.0 or later address the issue.

Risk and Exploitability

The CVSS score of 5.4 indicates moderate severity. EPSS data is unavailable, and the vulnerability is not listed in the CISA KEV catalog. The attack likely requires remote authenticated access; once an attacker has valid credentials, the hard-coded keys simplify extraction of confidential data and creation of legitimate‑looking authentication tokens. While the impact is moderate, the ability to tamper with auth mechanisms makes remediation urgent.

Generated by OpenCVE AI on September 22, 2026 at 23:21 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerabilities now by updating FTM deployments to the following Affected Product(s)Resolved by VRMFRemediation / First FixFinancial Transaction Manager (FTM) for RedHat OpenShift4.0.11.0 FTM 4.0.11.0 https://www.ibm.com/support/pages/node/7285661


OpenCVE Recommended Actions

  • Apply the IBM‑issued patch to upgrade FTM to version 4.0.11.0 or newer as documented in the official support article.
  • Re‑deploy the patched FTM image across all OpenShift clusters and verify that the hard‑coded key issue is resolved.
  • Before the patch is in place, restrict privileged user access to the transaction‑management services or isolate the FTM pods with network policies to limit exposure of sensitive data.

Generated by OpenCVE AI on September 22, 2026 at 23:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 22:15:00 +0000

Type Values Removed Values Added
Description IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to obtain sensitive information and forge authentication tags due to the use of hard-coded cryptographic keys and initialization vectors.
Title IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities
First Time appeared Ibm
Ibm financial Transaction Manager Ftmfor Redhat Openshift
Weaknesses CWE-327
CPEs cpe:2.3:a:ibm:financial_transaction_manager_ftmfor_redhat_openshift:4.0.6.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm financial Transaction Manager Ftmfor Redhat Openshift
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}


Subscriptions

Ibm Financial Transaction Manager Ftmfor Redhat Openshift
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-22T22:07:12.389Z

Reserved: 2026-07-28T19:52:22.861Z

Link: CVE-2026-18153

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-22T22:17:10.693

Modified: 2026-09-22T22:17:10.693

Link: CVE-2026-18153

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-22T23:45:18Z

Weaknesses
  • CWE-327

    Use of a Broken or Risky Cryptographic Algorithm