Impact
The vulnerability in IBM Financial Transaction Manager for RedHat OpenShift allows a remote authenticated attacker to forge user identities because the system performs improper authorization checks, effectively bypassing security controls. This flaw gives an attacker the capacity to act as another user, potentially enabling unauthorized transactions or data access. The weakness directly impacts confidentiality, integrity, and availability of the financial transaction system.
Affected Systems
IBM Financial Transaction Manager (FTM) for RedHat OpenShift is impacted. Versions 4.0.6.0 and earlier contain the flaw; the vendor recommends updating to 4.0.11.0 which resolves the issue. The product is available in RedHat OpenShift deployments.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity vulnerability. EPSS data is not available, so the probability of exploitation is unclear, but the flaw is listed in the vendor catalog and is not currently in the CISA KEV database. A remote attacker with valid credentials could exploit the weakness by sending forged user identity requests to the FTM service, thereby bypassing security controls. Given the need for authentication, the attack vector is an authenticated remote scenario, but once authenticated the attacker can act with potentially elevated privileges.
OpenCVE Enrichment