Impact
IBM Financial Transaction Manager for RedHat OpenShift allows a remote authenticated attacker to falsify transaction audit logs by sending specially crafted HTTP headers that are improperly validated. The flaw is a logging or monitoring failure (CWE‑778) and could cause the system to record inaccurate transaction histories, undermining forensic integrity and regulatory compliance.
Affected Systems
The vulnerability affects IBM Financial Transaction Manager (FTM) for RedHat OpenShift, particularly versions prior to 4.0.11.0 such as 4.0.6.0. The official fix is provided in release 4.0.11.0, which can be obtained through IBM support.
Risk and Exploitability
The CVSS score is 4.3, indicating a moderate severity. EPSS is not available and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires valid authentication to the FTM instance, so the attack vector is remote over HTTP. An attacker with an active session can modify audit logs, compromising integrity and potentially leading to undetected fraudulent activity. The risk is elevated for environments relying on FTM audit trails for compliance or monitoring.
OpenCVE Enrichment