Impact
IBM Financial Transaction Manager for RedHat OpenShift is vulnerable to a stored cross‑site scripting flaw in the NetworkAcknowledgement React component where malicious code can be inserted into stored network acknowledgement data. When an authenticated operator accesses this data, the injected script runs in the operator’s browser session, allowing the attacker to hijack the session and initiate unauthorized payment actions. The impact is direct compromise of operator privileges and potential financial loss.
Affected Systems
The vulnerability affects IBM Financial Transaction Manager (FTM) for RedHat OpenShift versions prior to 4.0.11.0. The vendor’s remedy is addressed in the 4.0.11.0 release, which contains the necessary UI update to prevent script injection.
Risk and Exploitability
The CVSS score of 9.3 indicates a high‑severity flaw; the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. It is likely exploitable via a standard web‑application attack vector: an authenticated operator must submit malicious content that is stored and later displayed. Once stored, the payload executes in any browser that renders the acknowledgement data, leading to immediate session hijack and privileged actions.
OpenCVE Enrichment