Impact
IBM Financial Transaction Manager for RedHat OpenShift could allow a remote attacker to obtain sensitive information due to the use of a hard‑coded or predictable cryptographic key. This flaw enables the decryption of protected data or the recovery of cryptographic material, potentially exposing confidential information and undermining data confidentiality.
Affected Systems
IBM Financial Transaction Manager (FTM) for RedHat OpenShift versions up to and including 4.0.6.0 are impacted. IBM has provided an official remediation that upgrades FTM to 4.0.11.0, eliminating the hard‑coded key. Any deployment running 4.0.6.0 or earlier should be reviewed and patched to the newer release.
Risk and Exploitability
With a CVSS score of 8 the vulnerability is high severity. The EPSS score is not available, so the likelihood of exploitation is uncertain, and it is not currently listed in the CISA KEV catalog. The attack vector is inferred as remote, requiring network access to the FTM instance, because the description specifies a remote attacker can obtain sensitive data. Exploiting the predictable key would allow unauthorized decryption of stored data or impersonation of FTM communications.
OpenCVE Enrichment