Description
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute unauthorized payment actions due to missing authorization checks.
Published: 2026-09-23
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: Unauthorized Transactions
Action: Patch Now
AI Analysis

Impact

The vulnerability in IBM Financial Transaction Manager (FTM) for RedHat OpenShift is a missing authorization check that allows an attacker who can reach the payment-processing interface to trigger unauthorized payment actions. The flaw is a classic authorization bypass (CWE‑862), enabling the attacker to make transactions that would otherwise require explicit approval, thereby compromising the integrity and confidentiality of financial data.

Affected Systems

IBM Financial Transaction Manager (FTM) for RedHat OpenShift, version 4.0.6.0, is vulnerable. IBM recommends updating deployments to version 4.0.11.0 or later, which contains the necessary authorization controls.

Risk and Exploitability

The CVSS base score of 7.1 indicates a high severity, and although the EPSS score is not available, the vulnerability is not listed in the CISA KEV catalog. The typical attack path requires remote access to the FTM payment API; a remote attacker can exploit the authorization bypass to initiate transactions without legitimate proof of payment rights. This scenario presents a moderate-to-high risk of financial loss and regulatory non-compliance, especially for organizations that rely on FTM for critical payment processing.

Generated by OpenCVE AI on September 23, 2026 at 16:13 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerabilities now by updating FTM deployments to the following Affected Product(s)Resolved by VRMFRemediation / First FixFinancial Transaction Manager (FTM) for RedHat OpenShift4.0.11.0 FTM 4.0.11.0 https://www.ibm.com/support/pages/node/7285661


OpenCVE Recommended Actions

  • Update IBM Financial Transaction Manager (FTM) for RedHat OpenShift to version 4.0.11.0 or later as per IBM recommendation.
  • Review any custom extensions or scripts that invoke payment actions to confirm they enforce proper authorization checks, addressing the missing authorization flaw (CWE‑862).
  • Implement network segmentation or firewall rules to limit access to the FTM payment endpoints to only authorized services or IP ranges, thereby reducing the attack surface until the patch can be applied.

Generated by OpenCVE AI on September 23, 2026 at 16:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 23 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
Description IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute unauthorized payment actions due to missing authorization checks.
Title IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities
First Time appeared Ibm
Ibm financial Transaction Manager Ftmfor Redhat Openshift
Weaknesses CWE-862
CPEs cpe:2.3:a:ibm:financial_transaction_manager_ftmfor_redhat_openshift:4.0.6.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm financial Transaction Manager Ftmfor Redhat Openshift
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L'}


Subscriptions

Ibm Financial Transaction Manager Ftmfor Redhat Openshift
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-23T16:18:52.616Z

Reserved: 2026-07-28T22:41:47.372Z

Link: CVE-2026-18177

cve-icon Vulnrichment

Updated: 2026-09-23T16:18:47.658Z

cve-icon NVD

Status : Received

Published: 2026-09-23T14:17:07.660

Modified: 2026-09-23T17:17:14.467

Link: CVE-2026-18177

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-23T16:15:06Z

Weaknesses