Impact
The vulnerability allows a remote attacker to acquire sensitive information because the system does not properly enforce mutual TLS authentication. This flaw can lead to confidential data exposure if the attacker can establish a TLS session that bypasses the expected certificate validation. The weakness is categorized as improper certificate validation, aligning with CWE-295.
Affected Systems
IBM Financial Transaction Manager (FTM) for RedHat OpenShift is impacted across versions starting with 4.0.6.0. The vendor’s remediation notes that deploying the 4.0.11.0 release resolves the issue for both OpenShift 4.0.11.0 and related builds.
Risk and Exploitability
The CVSS score of 3.7 indicates moderate potential impact, with the vulnerability rating currently not listed in CISA KEV. EPSS information is unavailable, so the exploitation likelihood is unknown but the access vector is inferred to be external over the network due to the TLS component. With the vulnerability residing in a remote-control component, the risk remains moderate pending patching.
OpenCVE Enrichment