Description
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute arbitrary code due to improper deserialization of untrusted data.
Published: 2026-09-22
Score: 9.8 Critical
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

IBM Financial Transaction Manager (FTM) for RedHat OpenShift contains an improper deserialization flaw that allows a remote attacker to execute arbitrary code by sending specially crafted data to the service; the weakness is identified as CWE-502 and can lead to a full compromise of the FTM host and any services interacting with it.

Affected Systems

All installations of IBM Financial Transaction Manager (FTM) for RedHat OpenShift running version 4.0.6.0 or earlier are affected; IBM recommends upgrading to the first‑fix release 4.0.11.0 or any later version that incorporates the deserialization patch.

Risk and Exploitability

The vulnerability scores a CVSS of 9.8, indicating critical severity, and while the EPSS score is not available it still represents a high exploit probability due to the lack of authentication requirements; it is not currently listed in CISA’s KEV catalog. The likely attack vector is a remote attacker transmitting malicious serialized payloads over the network to any FTM endpoint that processes untrusted data, allowing the attacker to run arbitrary code with the privileges of the FTM process.

Generated by OpenCVE AI on September 23, 2026 at 00:06 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerabilities now by updating FTM deployments to the following Affected Product(s)Resolved by VRMFRemediation / First FixFinancial Transaction Manager (FTM) for RedHat OpenShift4.0.11.0 FTM 4.0.11.0 https://www.ibm.com/support/pages/node/7285661


OpenCVE Recommended Actions

  • Immediately upgrade your IBM Financial Transaction Manager to version 4.0.11.0 or later to apply the deserialization fix.
  • If a patch cannot be applied immediately, isolate the FTM service behind a firewall or container network policy so that only trusted hosts can reach the endpoints that accept serialized data.
  • Implement application‑level input validation or proceed with a whitelist of acceptable serialized object types; this prevents untrusted payloads from triggering deserialization.
  • Continuously monitor FTM logs for abnormal serialization activity and configure alerts for repeated attempts to deserialize suspicious data.

Generated by OpenCVE AI on September 23, 2026 at 00:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Description IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute arbitrary code due to improper deserialization of untrusted data.
Title IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities
First Time appeared Ibm
Ibm financial Transaction Manager Ftmfor Redhat Openshift
Weaknesses CWE-502
CPEs cpe:2.3:a:ibm:financial_transaction_manager_ftmfor_redhat_openshift:4.0.6.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm financial Transaction Manager Ftmfor Redhat Openshift
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Ibm Financial Transaction Manager Ftmfor Redhat Openshift
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-22T22:11:59.192Z

Reserved: 2026-07-28T20:11:59.157Z

Link: CVE-2026-18163

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-22T23:17:06.600

Modified: 2026-09-22T23:17:06.600

Link: CVE-2026-18163

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-23T01:30:17Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data