Impact
This vulnerability is an open redirect in the IBM Financial Transaction Manager (FTM) for RedHat OpenShift, specifically within the PMP HostHeaderFilter at line 151. An unauthenticated attacker may send an HTTP request with a malicious Host header, causing authenticated operators to be redirected to attacker-controlled sites and thereby enabling credential phishing. The weakness is an insecure redirect reflected in user input, classified as CWE‑601, with no direct data or code compromise.
Affected Systems
The affected product is IBM Financial Transaction Manager (FTM) for RedHat OpenShift, versions earlier than 4.0.11.0. The vendor release 4.0.11.0 resolves the issue.
Risk and Exploitability
The CVSS score of 5.4 classifies the severity as medium. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote via an unauthenticated HTTP request to the PMP service. Because the redirect occurs without requiring authorization, operators could be maliciously lured into visiting disallowed URLs, potentially exposing credentials.
OpenCVE Enrichment