Impact
IBM Financial Transaction Manager for RedHat OpenShift can allow a remote attacker to execute arbitrary code because the application fails to neutralize user-controlled input used in a new Function constructor. This flaw gives full control over server-side JavaScript execution, allowing the attacker to run arbitrary commands, read or modify data, and potentially compromise the entire cluster.
Affected Systems
Affected systems are IBM Financial Transaction Manager (FTM) for RedHat OpenShift instances running version 4.0.6.0 and earlier. The vendor has released a remediation through VRMFRemediation / First Fix, updating to Financial Transaction Manager 4.0.11.0, which removes the insecure constructor usage.
Risk and Exploitability
The CVSS score of 9.8 indicates critical severity, but the EPSS score is unavailable, so the exploitation probability remains uncertain. It is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is remote submission of crafted input to a service exposed on OpenShift, which the application then evaluates, leading to remote code execution.
OpenCVE Enrichment