Description
IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to missing authentication on the Business Rules Manager commands REST endpoint (`CommandsResource.java:31`). A local actor can invoke unauthenticated commands to cause resource exhaustionand halt business-rule management functions.
Published: 2026-09-23
Score: 6.2 Medium
EPSS: n/a
KEV: No
Impact: Denial of Service via resource exhaustion due to missing authentication
Action: Patch Now
AI Analysis

Impact

IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to missing authentication on the Business Rules Manager commands REST endpoint. A local actor can invoke unauthenticated commands, causing resource exhaustion and halting business‑rule management functions. The vulnerability arises from a missing authentication check and carries the weakness CWE‑306.

Affected Systems

The affected product is IBM Financial Transaction Manager (FTM) for RedHat OpenShift, specifically versions up to and including 4.0.6.0. IBM recommends updating deployments to the fixed release FTM 4.0.11.0 to resolve the issue.

Risk and Exploitability

The CVSS score of 6.2 indicates moderate severity, while the EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog. The attack vector is inferred to be local or internal to the OpenShift cluster, where an attacker with cluster access can reach the exposed REST endpoint. The risk involves potential denial of service to business‑rule processing but does not provide a straightforward path to remote code execution or data exfiltration.

Generated by OpenCVE AI on September 23, 2026 at 17:41 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerabilities now by updating FTM deployments to the following Affected Product(s)Resolved by VRMFRemediation / First FixFinancial Transaction Manager (FTM) for RedHat OpenShift4.0.11.0 FTM 4.0.11.0 https://www.ibm.com/support/pages/node/7285661


OpenCVE Recommended Actions

  • Upgrade IBM Financial Transaction Manager to version 4.0.11.0 or later as advised by IBM.
  • If an upgrade cannot be applied immediately, restrict network access to the Business Rules Manager REST endpoint so that only authenticated and authorized services within the cluster can call it.
  • Ensure that appropriate role‑based access control is configured on OpenShift to enforce authentication and authorization for these endpoints.

Generated by OpenCVE AI on September 23, 2026 at 17:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 23 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Description IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to missing authentication on the Business Rules Manager commands REST endpoint (`CommandsResource.java:31`). A local actor can invoke unauthenticated commands to cause resource exhaustionand halt business-rule management functions.
Title IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities
First Time appeared Ibm
Ibm financial Transaction Manager Ftmfor Redhat Openshift
Weaknesses CWE-306
CPEs cpe:2.3:a:ibm:financial_transaction_manager_ftmfor_redhat_openshift:4.0.6.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm financial Transaction Manager Ftmfor Redhat Openshift
References
Metrics cvssV3_1

{'score': 6.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Ibm Financial Transaction Manager Ftmfor Redhat Openshift
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-23T17:47:30.600Z

Reserved: 2026-08-07T14:12:41.283Z

Link: CVE-2026-19267

cve-icon Vulnrichment

Updated: 2026-09-23T17:47:27.625Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-23T16:16:42.237

Modified: 2026-09-23T18:17:08.680

Link: CVE-2026-19267

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-23T19:30:07Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function