Impact
The vulnerability is a boolean expression injection in IBM Financial Transaction Manager for RedHat OpenShift that allows a remote attacker to manipulate database queries due to improper neutralisation of special elements. This can enable the attacker to modify, delete, or access data without authorization, undermining the confidentiality, integrity, and availability of transaction records. The weakness is classified as CWE-74, reflecting insufficient input handling that permits arbitrary query changes.
Affected Systems
IBM Financial Transaction Manager for RedHat OpenShift is affected. The issue appears in versions prior to 4.0.11.0, as identified by the CPE for 4.0.6.0 and earlier. IBM provides a fix through the VRMFRemediation for version 4.0.11.0; all deployments running older versions should update to this patched release.
Risk and Exploitability
The CVSS score of 8.2 indicates high severity. Although the EPSS score is not reported and the vulnerability is not listed in CISA KEV, the high score and the remote nature of the attack vector suggest a realistic exploitation threat. The attack vector is inferred to be remote, likely via exposed APIs or management interfaces that accept boolean expressions; an attacker must be able to reach the FTM service over the network to supply malicious input.
OpenCVE Enrichment