Impact
IBM Financial Transaction Manager for RedHat OpenShift is vulnerable to a form of RAG poisoning through an unauthenticated runbook upsert endpoint in the FTM AI agent server. The flaw allows an attacker to inject malicious runbook content into the agent's vector database, steering machine‑learning model calls that govern payment processing. Through manipulation of the AI‑driven MCP tool calls, the attacker could trigger unauthorized transfer of funds or exfiltrate confidential payment data. This constitutes a serious breach of payment integrity and confidentiality.
Affected Systems
Affected deployments are IBM Financial Transaction Manager (FTM) for RedHat OpenShift versions 4.0.6.0 and earlier. IBM recommends upgrading to 4.0.11.0, which incorporates the VRMF fix for the underlying flaw.
Risk and Exploitability
The CVSS score of 7.3 classifies the vulnerability as high severity. EPSS is not available and the flaw is not listed in the CISA KEV catalog. Because the attack path does not require authentication and directly targets the runbook API, an attacker with network access to the FTM AI agent can mount the exploit immediately. The absence of any authentication barrier elevates the practical risk, especially where the API is exposed to untrusted networks.
OpenCVE Enrichment