Impact
A missing authentication check in a critical function of IBM Financial Transaction Manager (FTM) for RedHat OpenShift can allow an attacker who can reach the system over a network to read sensitive data and change system settings. The vulnerability is rated with a CVSS score of 7.3, indicating a high impact if exploited. The weakness corresponds to CWE-306, which describes the absence of authentication control.
Affected Systems
IBM Financial Transaction Manager for RedHat OpenShift, version 4.0.6.0, is vulnerable. IBM recommends upgrading any affected deployments to version 4.0.11.0, which contains the fix. The vulnerability is relevant to all installations of FTM on the RedHat OpenShift platform that fall under the mentioned version range.
Risk and Exploitability
Because the function is exposed remotely and no authentication is required, an attacker can invoke it from outside the local network. The lack of EPSS data makes it uncertain how frequently the exploit is active, but the CVSS score reflects high severity. The vulnerability is not listed in the CISA KEV catalog, yet any system providing the affected function remains at risk until the patch is applied.
OpenCVE Enrichment