Impact
IBM Financial Transaction Manager for RedHat OpenShift contains a flaw that allows a remote authenticated attacker to obtain sensitive information by exploiting improper validation of symbolic links. The vulnerability is an instance of path traversal identified by CWE‑22, enabling the attacker to read files outside the intended scope and thus compromise confidentiality.
Affected Systems
IBM Financial Transaction Manager for RedHat OpenShift, version 4.0.6.0 and earlier, is affected. IBM recommends upgrading deployments to version 4.0.11.0, which contains the fix for this issue.
Risk and Exploitability
The CVSS score of 9.9 reflects high severity, but the exploit requires valid authenticated access to the system and does not appear to be publicly exploitable without credentials. The EPSS score is not available, and the issue is not listed in the CISA KEV catalog, indicating that it may not be actively exploited yet. Nevertheless, the high severity and remote authenticated nature warrant a prompt response.
OpenCVE Enrichment