Impact
The vulnerability is an XML external entity injection flaw (CWE‑611) present in all 4.x releases of IBM Financial Transaction Manager for RedHat OpenShift. A remote authenticated attacker can supply crafted XML input that forces FTM to resolve external entities, enabling the attacker to read sensitive data such as configuration files, credentials, or transaction records.
Affected Systems
The affected product is IBM Financial Transaction Manager (FTM) for RedHat OpenShift, versions 4.x, specifically all releases prior to 4.0.11.0. The vendor recommendation is to upgrade to FTM 4.0.11.0. The solution details are available on IBM support pages.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. Because the exploit requires valid user credentials, the attack vector is limited to authenticated users; it is not listed in CISA KEV and EPSS data is not available. Nonetheless, the potential for sensitive data exposure warrants timely remediation.
OpenCVE Enrichment