Impact
IBM Financial Transaction Manager for RedHat OpenShift is vulnerable to unauthenticated remote code execution through an insecure Java native deserialization flaw on the PayDir Business Rules Manager RMI SSL endpoint. An attacker on an adjacent network can send a crafted serialized payload that causes the JVM to instantiate malicious objects and execute arbitrary code. This grants full control over the PayDir service, allowing the attacker to read all PayDir credentials, modify payment business rules, and potentially compromise the entire payment processing infrastructure, impacting confidentiality, integrity, and availability.
Affected Systems
IBM Financial Transaction Manager (FTM) for RedHat OpenShift version 4.0.6.0 is affected. The vendor recommends upgrading to version 4.0.11.0 to remediate the issue.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.8, classifying it as high severity. The EPSS score is not available, and it is not listed in the CISA KEV catalog, but these factors do not mitigate the urgency. An attacker who can reach the PayDir Business Rules Manager RMI SSL service without authentication can exploit this flaw, which makes it highly exploitable in a shared or adjacent network environment. The combination of a severe impact score and ease of exploitation indicates a significant risk that requires prompt action.
OpenCVE Enrichment