Impact
IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to missing authentication on the Business Rules Manager commands REST endpoint. A local actor can invoke unauthenticated commands, causing resource exhaustion and halting business‑rule management functions. The vulnerability arises from a missing authentication check and carries the weakness CWE‑306.
Affected Systems
The affected product is IBM Financial Transaction Manager (FTM) for RedHat OpenShift, specifically versions up to and including 4.0.6.0. IBM recommends updating deployments to the fixed release FTM 4.0.11.0 to resolve the issue.
Risk and Exploitability
The CVSS score of 6.2 indicates moderate severity, while the EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog. The attack vector is inferred to be local or internal to the OpenShift cluster, where an attacker with cluster access can reach the exposed REST endpoint. The risk involves potential denial of service to business‑rule processing but does not provide a straightforward path to remote code execution or data exfiltration.
OpenCVE Enrichment