Impact
The vulnerability in IBM Financial Transaction Manager (FTM) for RedHat OpenShift is a missing authorization check that allows an attacker who can reach the payment-processing interface to trigger unauthorized payment actions. The flaw is a classic authorization bypass (CWE‑862), enabling the attacker to make transactions that would otherwise require explicit approval, thereby compromising the integrity and confidentiality of financial data.
Affected Systems
IBM Financial Transaction Manager (FTM) for RedHat OpenShift, version 4.0.6.0, is vulnerable. IBM recommends updating deployments to version 4.0.11.0 or later, which contains the necessary authorization controls.
Risk and Exploitability
The CVSS base score of 7.1 indicates a high severity, and although the EPSS score is not available, the vulnerability is not listed in the CISA KEV catalog. The typical attack path requires remote access to the FTM payment API; a remote attacker can exploit the authorization bypass to initiate transactions without legitimate proof of payment rights. This scenario presents a moderate-to-high risk of financial loss and regulatory non-compliance, especially for organizations that rely on FTM for critical payment processing.
OpenCVE Enrichment