Impact
The vulnerability in IBM Financial Transaction Manager for RedHat OpenShift allows a remote attacker to terminate active chat sessions because the system does not properly verify authorizations. This flaw permits the attacker to disrupt legitimate user communication by forcing session termination, resulting in denial of service to those users. The weakness is an improper authorization flaw, labeled CWE-862, indicating that requests are accepted without sufficient checks.
Affected Systems
IBM’s Financial Transaction Manager (FTM) for RedHat OpenShift, specifically version 4.0.6.0 as identified by the CPE string, is affected. The vendor recommends upgrading to version 4.0.11.0, which incorporates remediation for the authorization flaw.
Risk and Exploitability
The CVSS score of 6.5 places this vulnerability in the medium severity range. No EPSS information is available, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is remote and requires that the attacker can access the FTM APIs; the flaw is more of an improper authorization than an authentication bypass, so an attacker needs to be able to submit requests to the session‑clear endpoint. The likelihood of exploitation is uncertain, but since the flaw allows disruption of service, it poses a nontrivial risk to operations.
OpenCVE Enrichment