Financial Transaction Manager Ftmfor Redhat Openshift IBM Financial Transaction Manager Ftmfor Redhat Openshift

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in IBM Financial Transaction Manager Ftmfor Redhat Openshift.

By the Year

In 2026 there have been 46 vulnerabilities in IBM Financial Transaction Manager Ftmfor Redhat Openshift with an average score of 7.5 out of ten.

Year Vulnerabilities Average Score
2026 46 7.45

It may take a day or so for new Financial Transaction Manager Ftmfor Redhat Openshift vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent IBM Financial Transaction Manager Ftmfor Redhat Openshift Security Vulnerabilities

IBM FTM OpenShift BLM REST endpoint lacks auth DoS
CVE-2026-19267 6.2 - Medium - September 23, 2026

IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to missing authentication on the Business Rules Manager commands REST endpoint (`CommandsResource.java:31`). A local actor can invoke unauthenticated commands to cause resource exhaustionand halt business-rule management functions.

Missing Authentication for Critical Function

IBM FTM OpenShift SQL Injection via Boolean Expression Flaw
CVE-2026-19179 8.2 - High - September 23, 2026

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to manipulate database queries due to improper neutralization of special elements in a boolean expression.

Injection

IBM FTM on RedHat OpenShift privilege escalation via improper privilege mgmt
CVE-2026-19087 4.4 - Medium - September 23, 2026

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a local attacker to achieve privilege escalation within the container due to improper privilege management.

Execution with Unnecessary Privileges

CVE-2026-18875 IBM FTM on RH OpenShift: RAG Poisoning via Unauth Runbook Upsert
CVE-2026-18875 7.3 - High - September 23, 2026

IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to RAG poisoning via unauthenticated runbook upsert (CWE-74) in the FTM AI agent server (api.vectordb.runbooks.js:51). An unauthenticated attacker can insert malicious runbook content into the agent's vector database to steer AI-driven MCP tool calls, potentially triggering unauthorized payment actions or exfiltrating payment data.

Injection

Stored XSS in IBM FTM UI Component Enables Session Hijack
CVE-2026-18872 9.3 - Critical - September 23, 2026

IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to stored cross-site scripting (CWE-79) in the FTM UI NetworkAcknowledgement React component (NetworkAcknowledgement.jsx:42). A malicious actor can inject script into stored network acknowledgement data that executes in authenticated operator browsers, enabling session hijacking and unauthorized operator-level payment actions.

XSS

IBM FTM OpenShift HostHeaderFilter Open Redirect
CVE-2026-18505 5.4 - Medium - September 23, 2026

IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to open redirect in the PMP `HostHeaderFilter` (`HostHeaderFilter.java:151`). An unauthenticated attacker can craft a request with a manipulated `Host` header to redirect authenticated operators to attacker-controlled sites, enabling credential phishing.

Open Redirect

FTM RMI SSL endpoint: Java deserialization RCE
CVE-2026-18490 8.8 - High - September 23, 2026

IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to unauthenticated remote code execution via Java native deserialization on the PayDir Business Rules Manager RMI SSL endpoint (BrmRMISSLServerSocketFactory.java:95, EP8). An adjacent-network attacker can deliver a crafted serialized payload to achieve arbitrary code execution, exposing all PayDir credentials and enabling manipulation of payment business rules.

Marshaling, Unmarshaling

IBM FTM on RedHat OpenShift: Missing Auth Enables Remote Info Leak & Config Change
CVE-2026-18185 7.3 - High - September 23, 2026

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to access sensitive information and modify system configurations due to missing authentication for a critical function.

Missing Authentication for Critical Function

IBM FTM XXE Injection Allows Remote Info Disclosure
CVE-2026-18184 7.4 - High - September 23, 2026

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive information due to an XML external entity (XXE) injection flaw.

XXE

IBM FTM on OpenShift: HardCoded Crypto Key Allows Auth Bypass
CVE-2026-18181 8.1 - High - September 23, 2026

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to bypass authentication and access sensitive information due to a hard-coded cryptographic key.

Use of Hard-coded Cryptographic Key

FTM RedHat OpenShift SQLi Allows Remote Authenticated Info Disclosure
CVE-2026-18180 6.5 - Medium - September 23, 2026

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to obtain sensitive information due to SQL injection.

SQL Injection

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could
CVE-2026-18179 6.5 - Medium - September 23, 2026

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to clear active chat sessions due to improper authorization.

AuthZ

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could
CVE-2026-18177 7.1 - High - September 23, 2026

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute unauthorized payment actions due to missing authorization checks.

AuthZ

IBM FTM on OpenShift Cleartext Data Leak
CVE-2026-18176 7.4 - High - September 22, 2026

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive information due to cleartext transmission of sensitive information.

Cleartext Transmission of Sensitive Information

IBM FTM OpenShift: Mutual TLS Bypass Exposes Sensitive Data
CVE-2026-18173 3.7 - Low - September 22, 2026

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive information due to improper enforcement of mutual TLS authentication.

Improper Certificate Validation

IBM FTM XXE Remote Info Disclosure
CVE-2026-18172 7.4 - High - September 22, 2026

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive information due to improper restriction of XML external entity references.

XXE

IBM FTM Remote Authenticated Info Disclosure via Symlink Validation Flaw
CVE-2026-18169 9.9 - Critical - September 22, 2026

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to obtain sensitive information due to improper validation of symbolic links.

Directory traversal

IBM FTM DoS via Unrestricted Resource Allocation (CVE-2026-18170)
CVE-2026-18170 6.5 - Medium - September 22, 2026

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to cause a denial of service due to allocation of resources without limits or throttling.

Allocation of Resources Without Limits or Throttling

IBM FTM for OpenShift: Remote Code Exec via Unsafe Deserialization
CVE-2026-18163 9.8 - Critical - September 22, 2026

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute arbitrary code due to improper deserialization of untrusted data.

Marshaling, Unmarshaling

IBM FTM OpenShift RCE via unsafe Function constructor
CVE-2026-18162 9.8 - Critical - September 22, 2026

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute arbitrary code due to improper neutralization of user-controlled input within the new Function constructor.

Code Injection

FTM for RedHat OpenShift Authenticated Header Flaw Enables Log Forgery
CVE-2026-18161 4.3 - Medium - September 22, 2026

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to falsify transaction audit logs due to improper validation of a client-supplied HTTP header.

Insufficient Logging

FTM Auth Bypass via Identity Forgery in IBM FTM on OpenShift
CVE-2026-18156 6.5 - Medium - September 22, 2026

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to bypass security controls by forging user identities due to improper authorization.

AuthZ

IBM FTM for RedHat OpenShift: Hard-Coded Crypto Key Enables Remote Info Disclosure
CVE-2026-18154 8 - High - September 22, 2026

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive information due to the use of a hard-coded or predictable cryptographic key.

Use of Hard-coded Cryptographic Key

IBM FTM on OpenShift: Hard-Coded Keys Enable Auth Info Disclosure & Tag Forgery
CVE-2026-18153 5.4 - Medium - September 22, 2026

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to obtain sensitive information and forge authentication tags due to the use of hard-coded cryptographic keys and initialization vectors.

Use of a Broken or Risky Cryptographic Algorithm

IBM FTM OpenShift Remote Signature Forgery Vulnerability
CVE-2026-18152 7.4 - High - September 22, 2026

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to forge validly-signed messages due to improper verification of cryptographic signatures.

Improper Verification of Cryptographic Signature

IBM FTM Remote ESQL Injection via Improper Neutralization
CVE-2026-18137 8.1 - High - September 22, 2026

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute arbitrary ESQL commands due to improper neutralization of special elements used in an ESQL command.

SQL Injection

IBM FTM OpenShift Cleartext Data Leak
CVE-2026-18134 7.5 - High - September 22, 2026

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive information due to cleartext transmission of sensitive information.

Cleartext Transmission of Sensitive Information

IBM FTM Path Traversal Enables Authenticated File Modification on OpenShift
CVE-2026-18133 5.4 - Medium - September 22, 2026

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to modify server files due to path traversal.

Directory traversal

IBM FTM RedHat OpenShift: AuthZ Bypass Enables Unauthorized Payment Mutation
CVE-2026-18132 6.5 - Medium - September 22, 2026

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to perform unauthorized payment mutation actions due to missing authorization.

AuthZ

IBM FTM XSS: Remote JS exec via HTML input on RedHat OpenShift
CVE-2026-18131 8.2 - High - September 22, 2026

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute arbitrary JavaScript in an authenticated user's browser due to improper neutralization of HTML input.

XSS

IBM FTM Local Credential Disclosure via Insufficient Protection
CVE-2026-18124 6.5 - Medium - September 22, 2026

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a local attacker to obtain sensitive information due to insufficiently protected credentials.

Insufficiently Protected Credentials

IBM FTM OpenShift: Remote DoS via Improper Reflection
CVE-2026-18123 7.6 - High - September 22, 2026

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to cause a denial of service due to the improper use of reflection with externally controlled input.

Reflection Injection

IBM FTM Remote File Read via Path Canonicalization on OpenShift
CVE-2026-18114 6.5 - Medium - September 22, 2026

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to read arbitrary files due to improper path canonicalization.

Directory traversal

IBM FTM Remote Authenticated Buffer Overflow in RedHat OpenShift
CVE-2026-18095 8.5 - High - September 22, 2026

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to execute arbitrary code due to a buffer overflow.

Memory Corruption

IBM FTM OpenShift Auth Bypass Remote
CVE-2026-18074 8.2 - High - September 22, 2026

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to perform unauthorized actions due to improper authentication and missing authorization.

authentification

IBM FTM Local SSRF Enables Sensitive Data Exposure
CVE-2026-18066 7.9 - High - September 22, 2026

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a local attacker to obtain sensitive information and trigger unauthorized actions due to server-side request forgery.

SSRF

Local Cmd Exec via Untrusted Control Sphere in IBM FTM on OpenShift
CVE-2026-17647 8.8 - High - September 22, 2026

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a local attacker to execute arbitrary commands due to the inclusion of functionality from an untrusted control sphere.

Inclusion of Functionality from Untrusted Control Sphere

IBM FTM on OpenShift: XXE Allows Remote Authenticated Info Leak
CVE-2026-17646 8.5 - High - September 22, 2026

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to obtain sensitive information due to improper restriction of XML external entity references.

XXE

IBM FTM on OpenShift: Authenticated Escalation via Misconfigured Privileges
CVE-2026-17645 9.1 - Critical - September 22, 2026

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to gain elevated privileges due to improper privilege management.

Improper Privilege Management

FTM RedHat OpenShift Local Auth Bypass via Hard-coded Credentials
CVE-2026-17644 8.8 - High - September 22, 2026

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a local attacker to gain unauthorized access to sensitive information and modify transaction data due to the use of hard-coded credentials.

Use of Hard-coded Credentials

IBM FTM RedHat OpenShift CVE Local Auth Credentials Leak
CVE-2026-17643 8.8 - High - September 22, 2026

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a local attacker to obtain sensitive information and perform unauthorized actions due to insufficiently protected credentials.

Insufficiently Protected Credentials

IBM FTM OpenShift Deserialization RCE for Adjacent-Network Attackers
CVE-2026-17637 8.8 - High - September 22, 2026

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow an adjacent-network attacker to execute arbitrary code due to deserialization of untrusted data.

Marshaling, Unmarshaling

IBM FTM/RH OpenShift Remote Auth RCE via Quantity Validation
CVE-2026-17636 8.8 - High - September 22, 2026

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to execute arbitrary code due to improper validation of a specified quantity.

Memory Corruption

IBM FTM HTTP Method Misconfiguration Permits Remote Unauthorized Actions
CVE-2026-17635 9.1 - Critical - September 22, 2026

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to perform unauthorized actions due to improper configuration of HTTP method-based security constraints.

Missing Authentication for Critical Function

IBM FTM 4.0.6.0 Cleartext Data Transmission Vulnerability
CVE-2026-17620 5.3 - Medium - September 22, 2026

IBM Financial Transaction Manager (FTM) for RedHat OpenShift 4.0.6.0 through 4.0.6.0.0.6.0 Refresh (Operator 4.4.6+20260807.081800)4.0.7.04.0.8.04.0.9.04.0.10.0 Interim Fix 064 IBM Financial Transaction Manager transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

Unprotected Transport of Credentials

FTM for OpenShift: Remote Unauth RCE & DoS via Improper Auth
CVE-2026-17618 7.3 - High - September 22, 2026

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote unauthenticated attacker to view and modify sensitive information and cause a denial of service due to improper authorization.

AuthZ

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for IBM Financial Transaction Manager Ftmfor Redhat Openshift or by IBM? Click the Watch button to subscribe.

IBM
Vendor

subscribe