Impact
IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to an XML external entity (XXE) injection flaw that can be triggered by a remote attacker. The flaw allows the attacker to retrieve arbitrary files and other sensitive information from the server’s file system. As the system processes untrusted XML input without disabling external entity resolution, the weakness is identified as CWE‑611.
Affected Systems
The affected component is IBM Financial Transaction Manager (FTM) for RedHat OpenShift with a reported version of 4.0.6.0. IBM has released a patch in FTM 4.0.11.0 that resolves the issue. All deployments running 4.0.6.0 should be updated to the fixed release.
Risk and Exploitability
The vulnerability carries a CVSS v3.1 score of 7.4, indicating high severity. An EPSS score is not available and the issue is not listed in the CISA KEV catalog. The likely attack vector is remote, with the attacker sending engineered XML payloads over the network to trigger the XXE. The impact is data exposure of files and configuration information, potentially allowing further compromise of the environment.
OpenCVE Enrichment