Impact
IBM Financial Transaction Manager (FTM) for RedHat OpenShift contains an improper deserialization flaw that allows a remote attacker to execute arbitrary code by sending specially crafted data to the service; the weakness is identified as CWE-502 and can lead to a full compromise of the FTM host and any services interacting with it.
Affected Systems
All installations of IBM Financial Transaction Manager (FTM) for RedHat OpenShift running version 4.0.6.0 or earlier are affected; IBM recommends upgrading to the first‑fix release 4.0.11.0 or any later version that incorporates the deserialization patch.
Risk and Exploitability
The vulnerability scores a CVSS of 9.8, indicating critical severity, and while the EPSS score is not available it still represents a high exploit probability due to the lack of authentication requirements; it is not currently listed in CISA’s KEV catalog. The likely attack vector is a remote attacker transmitting malicious serialized payloads over the network to any FTM endpoint that processes untrusted data, allowing the attacker to run arbitrary code with the privileges of the FTM process.
OpenCVE Enrichment