Impact
IBM Financial Transaction Manager for RedHat OpenShift contains a flaw that permits a local attacker inside the container to gain higher privileges due to improper privilege management. This elevation allows the attacker to run arbitrary commands with increased authority, potentially compromising internal transaction data and enabling further abuse of the container environment.
Affected Systems
IBM Financial Transaction Manager for RedHat OpenShift versions prior to 4.0.11.0, notably 4.0.6.0 and earlier, are impacted. The vulnerability is identified by the CPE string cpe:2.3:a:ibm:financial_transaction_manager_ftmfor_redhat_openshift:4.0.6.0:*:*:*:*:*:*.
Risk and Exploitability
The CVSS score of 4.4 classifies this issue as moderate. EPSS is not available and the vulnerability is not listed in CISA KEV, indicating no widespread exploitation has been reported. The attack requires local access to the OpenShift container, so an attacker must already have compromised the container or host node. While the medium severity suggests a need for timely action, the current evidence points to a low to moderate likelihood of exploitation, yet the impact of privilege escalation justifies prompt remediation.
OpenCVE Enrichment