Impact
The vulnerability arises from cleartext transmission of sensitive data during IBM Financial Transaction Manager operations, enabling a remote attacker to intercept and read confidential transaction information. This flaw directly compromises the confidentiality of data handled by the system and is classified as CWE‑319. No active intrusion or privilege escalation is required; the mere ability to observe traffic is sufficient to exploit the weakness.
Affected Systems
IBM Financial Transaction Manager (FTM) for RedHat OpenShift is impacted. The flaw affects deployments running version 4.0.6.0. IBM recommends upgrading to version 4.0.11.0 to eliminate the vulnerability.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.4, indicating a high risk of severe impact if exploited. The EPSS score is not available, and the issue is not listed in the CISA Known Exploited Vulnerabilities catalog. The attack vector is remote, requiring network access to the FTM instance and the ability to capture traffic. An attacker who can intercept cleartext traffic between clients and the FTM server could retrieve sensitive transaction data, potentially leading to financial loss or regulatory non‑compliance.
OpenCVE Enrichment