Impact
The vulnerability arises from unchecked resource allocation in IBM Financial Transaction Manager, allowing a remote attacker to trigger a denial of service by exhausting available resources. This is a classic resource exhaustion flaw (CWE‑770). When triggered, the FTM service may become unresponsive, leading to interruption of transaction processing and overall system availability.
Affected Systems
The flaw affects IBM Financial Transaction Manager for RedHat OpenShift versions prior to 4.0.11.0, notably 4.0.6.0 and earlier. The product is deployed in RedHat OpenShift clusters as part of IBM’s Financial Transaction Manager offering. The advisory specifically mentions FTM 4.0.11.0 as the first fix.
Risk and Exploitability
The CVSS base score is 6.5, indicating a moderate severity and an available attack vector that appears to be remote. EPSS is not available, so exploitation probability is uncertain. The vulnerability is not listed in CISA’s KEV catalog. Attackers could remotely send crafted requests or trigger internal processes to force the FTM instance to allocate unlimited resources, causing a denial of service. Blocking such traffic or applying the patch reduces this risk.
OpenCVE Enrichment