Impact
IBM Financial Transaction Manager for RedHat OpenShift may contain a parameter that permits a remote authenticated attacker to inject SQL statements. The flaw can expose confidential transaction data stored in the underlying database, causing loss of confidentiality.
Affected Systems
Vendors: IBM. Product: Financial Transaction Manager for RedHat OpenShift, version 4.0.6.0. IBM recommends upgrading to 4.0.11.0, which contains the fix.
Risk and Exploitability
The vulnerability has a CVSS score of 6.5 indicating moderate severity. The EPSS score is not available and the vulnerability is not listed in CISA KEV. The attack requires authenticated access and can be performed over a remote network. Since the flaw is a classic SQL injection, an attacker could retrieve any data from the database, subject to access control policies on the application.
OpenCVE Enrichment