IBM Financial Transaction Manager Ftmfor Redhat Openshift
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in IBM Financial Transaction Manager Ftmfor Redhat Openshift.
By the Year
In 2026 there have been 46 vulnerabilities in IBM Financial Transaction Manager Ftmfor Redhat Openshift with an average score of 7.5 out of ten.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 46 | 7.45 |
It may take a day or so for new Financial Transaction Manager Ftmfor Redhat Openshift vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent IBM Financial Transaction Manager Ftmfor Redhat Openshift Security Vulnerabilities
IBM FTM OpenShift BLM REST endpoint lacks auth DoS
CVE-2026-19267
6.2 - Medium
- September 23, 2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to missing authentication on the Business Rules Manager commands REST endpoint (`CommandsResource.java:31`). A local actor can invoke unauthenticated commands to cause resource exhaustionand halt business-rule management functions.
Missing Authentication for Critical Function
IBM FTM OpenShift SQL Injection via Boolean Expression Flaw
CVE-2026-19179
8.2 - High
- September 23, 2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to manipulate database queries due to improper neutralization of special elements in a boolean expression.
Injection
IBM FTM on RedHat OpenShift privilege escalation via improper privilege mgmt
CVE-2026-19087
4.4 - Medium
- September 23, 2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a local attacker to achieve privilege escalation within the container due to improper privilege management.
Execution with Unnecessary Privileges
CVE-2026-18875 IBM FTM on RH OpenShift: RAG Poisoning via Unauth Runbook Upsert
CVE-2026-18875
7.3 - High
- September 23, 2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to RAG poisoning via unauthenticated runbook upsert (CWE-74) in the FTM AI agent server (api.vectordb.runbooks.js:51). An unauthenticated attacker can insert malicious runbook content into the agent's vector database to steer AI-driven MCP tool calls, potentially triggering unauthorized payment actions or exfiltrating payment data.
Injection
Stored XSS in IBM FTM UI Component Enables Session Hijack
CVE-2026-18872
9.3 - Critical
- September 23, 2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to stored cross-site scripting (CWE-79) in the FTM UI NetworkAcknowledgement React component (NetworkAcknowledgement.jsx:42). A malicious actor can inject script into stored network acknowledgement data that executes in authenticated operator browsers, enabling session hijacking and unauthorized operator-level payment actions.
XSS
IBM FTM OpenShift HostHeaderFilter Open Redirect
CVE-2026-18505
5.4 - Medium
- September 23, 2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to open redirect in the PMP `HostHeaderFilter` (`HostHeaderFilter.java:151`). An unauthenticated attacker can craft a request with a manipulated `Host` header to redirect authenticated operators to attacker-controlled sites, enabling credential phishing.
Open Redirect
FTM RMI SSL endpoint: Java deserialization RCE
CVE-2026-18490
8.8 - High
- September 23, 2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to unauthenticated remote code execution via Java native deserialization on the PayDir Business Rules Manager RMI SSL endpoint (BrmRMISSLServerSocketFactory.java:95, EP8). An adjacent-network attacker can deliver a crafted serialized payload to achieve arbitrary code execution, exposing all PayDir credentials and enabling manipulation of payment business rules.
Marshaling, Unmarshaling
IBM FTM on RedHat OpenShift: Missing Auth Enables Remote Info Leak & Config Change
CVE-2026-18185
7.3 - High
- September 23, 2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to access sensitive information and modify system configurations due to missing authentication for a critical function.
Missing Authentication for Critical Function
IBM FTM XXE Injection Allows Remote Info Disclosure
CVE-2026-18184
7.4 - High
- September 23, 2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive information due to an XML external entity (XXE) injection flaw.
XXE
IBM FTM on OpenShift: HardCoded Crypto Key Allows Auth Bypass
CVE-2026-18181
8.1 - High
- September 23, 2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to bypass authentication and access sensitive information due to a hard-coded cryptographic key.
Use of Hard-coded Cryptographic Key
FTM RedHat OpenShift SQLi Allows Remote Authenticated Info Disclosure
CVE-2026-18180
6.5 - Medium
- September 23, 2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to obtain sensitive information due to SQL injection.
SQL Injection
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could
CVE-2026-18179
6.5 - Medium
- September 23, 2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to clear active chat sessions due to improper authorization.
AuthZ
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could
CVE-2026-18177
7.1 - High
- September 23, 2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute unauthorized payment actions due to missing authorization checks.
AuthZ
IBM FTM on OpenShift Cleartext Data Leak
CVE-2026-18176
7.4 - High
- September 22, 2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive information due to cleartext transmission of sensitive information.
Cleartext Transmission of Sensitive Information
IBM FTM OpenShift: Mutual TLS Bypass Exposes Sensitive Data
CVE-2026-18173
3.7 - Low
- September 22, 2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive information due to improper enforcement of mutual TLS authentication.
Improper Certificate Validation
IBM FTM XXE Remote Info Disclosure
CVE-2026-18172
7.4 - High
- September 22, 2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive information due to improper restriction of XML external entity references.
XXE
IBM FTM Remote Authenticated Info Disclosure via Symlink Validation Flaw
CVE-2026-18169
9.9 - Critical
- September 22, 2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to obtain sensitive information due to improper validation of symbolic links.
Directory traversal
IBM FTM DoS via Unrestricted Resource Allocation (CVE-2026-18170)
CVE-2026-18170
6.5 - Medium
- September 22, 2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to cause a denial of service due to allocation of resources without limits or throttling.
Allocation of Resources Without Limits or Throttling
IBM FTM for OpenShift: Remote Code Exec via Unsafe Deserialization
CVE-2026-18163
9.8 - Critical
- September 22, 2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute arbitrary code due to improper deserialization of untrusted data.
Marshaling, Unmarshaling
IBM FTM OpenShift RCE via unsafe Function constructor
CVE-2026-18162
9.8 - Critical
- September 22, 2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute arbitrary code due to improper neutralization of user-controlled input within the new Function constructor.
Code Injection
FTM for RedHat OpenShift Authenticated Header Flaw Enables Log Forgery
CVE-2026-18161
4.3 - Medium
- September 22, 2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to falsify transaction audit logs due to improper validation of a client-supplied HTTP header.
Insufficient Logging
FTM Auth Bypass via Identity Forgery in IBM FTM on OpenShift
CVE-2026-18156
6.5 - Medium
- September 22, 2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to bypass security controls by forging user identities due to improper authorization.
AuthZ
IBM FTM for RedHat OpenShift: Hard-Coded Crypto Key Enables Remote Info Disclosure
CVE-2026-18154
8 - High
- September 22, 2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive information due to the use of a hard-coded or predictable cryptographic key.
Use of Hard-coded Cryptographic Key
IBM FTM on OpenShift: Hard-Coded Keys Enable Auth Info Disclosure & Tag Forgery
CVE-2026-18153
5.4 - Medium
- September 22, 2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to obtain sensitive information and forge authentication tags due to the use of hard-coded cryptographic keys and initialization vectors.
Use of a Broken or Risky Cryptographic Algorithm
IBM FTM OpenShift Remote Signature Forgery Vulnerability
CVE-2026-18152
7.4 - High
- September 22, 2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to forge validly-signed messages due to improper verification of cryptographic signatures.
Improper Verification of Cryptographic Signature
IBM FTM Remote ESQL Injection via Improper Neutralization
CVE-2026-18137
8.1 - High
- September 22, 2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute arbitrary ESQL commands due to improper neutralization of special elements used in an ESQL command.
SQL Injection
IBM FTM OpenShift Cleartext Data Leak
CVE-2026-18134
7.5 - High
- September 22, 2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive information due to cleartext transmission of sensitive information.
Cleartext Transmission of Sensitive Information
IBM FTM Path Traversal Enables Authenticated File Modification on OpenShift
CVE-2026-18133
5.4 - Medium
- September 22, 2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to modify server files due to path traversal.
Directory traversal
IBM FTM RedHat OpenShift: AuthZ Bypass Enables Unauthorized Payment Mutation
CVE-2026-18132
6.5 - Medium
- September 22, 2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to perform unauthorized payment mutation actions due to missing authorization.
AuthZ
IBM FTM XSS: Remote JS exec via HTML input on RedHat OpenShift
CVE-2026-18131
8.2 - High
- September 22, 2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute arbitrary JavaScript in an authenticated user's browser due to improper neutralization of HTML input.
XSS
IBM FTM Local Credential Disclosure via Insufficient Protection
CVE-2026-18124
6.5 - Medium
- September 22, 2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a local attacker to obtain sensitive information due to insufficiently protected credentials.
Insufficiently Protected Credentials
IBM FTM OpenShift: Remote DoS via Improper Reflection
CVE-2026-18123
7.6 - High
- September 22, 2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to cause a denial of service due to the improper use of reflection with externally controlled input.
Reflection Injection
IBM FTM Remote File Read via Path Canonicalization on OpenShift
CVE-2026-18114
6.5 - Medium
- September 22, 2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to read arbitrary files due to improper path canonicalization.
Directory traversal
IBM FTM Remote Authenticated Buffer Overflow in RedHat OpenShift
CVE-2026-18095
8.5 - High
- September 22, 2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to execute arbitrary code due to a buffer overflow.
Memory Corruption
IBM FTM OpenShift Auth Bypass Remote
CVE-2026-18074
8.2 - High
- September 22, 2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to perform unauthorized actions due to improper authentication and missing authorization.
authentification
IBM FTM Local SSRF Enables Sensitive Data Exposure
CVE-2026-18066
7.9 - High
- September 22, 2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a local attacker to obtain sensitive information and trigger unauthorized actions due to server-side request forgery.
SSRF
Local Cmd Exec via Untrusted Control Sphere in IBM FTM on OpenShift
CVE-2026-17647
8.8 - High
- September 22, 2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a local attacker to execute arbitrary commands due to the inclusion of functionality from an untrusted control sphere.
Inclusion of Functionality from Untrusted Control Sphere
IBM FTM on OpenShift: XXE Allows Remote Authenticated Info Leak
CVE-2026-17646
8.5 - High
- September 22, 2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to obtain sensitive information due to improper restriction of XML external entity references.
XXE
IBM FTM on OpenShift: Authenticated Escalation via Misconfigured Privileges
CVE-2026-17645
9.1 - Critical
- September 22, 2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to gain elevated privileges due to improper privilege management.
Improper Privilege Management
FTM RedHat OpenShift Local Auth Bypass via Hard-coded Credentials
CVE-2026-17644
8.8 - High
- September 22, 2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a local attacker to gain unauthorized access to sensitive information and modify transaction data due to the use of hard-coded credentials.
Use of Hard-coded Credentials
IBM FTM RedHat OpenShift CVE Local Auth Credentials Leak
CVE-2026-17643
8.8 - High
- September 22, 2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a local attacker to obtain sensitive information and perform unauthorized actions due to insufficiently protected credentials.
Insufficiently Protected Credentials
IBM FTM OpenShift Deserialization RCE for Adjacent-Network Attackers
CVE-2026-17637
8.8 - High
- September 22, 2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow an adjacent-network attacker to execute arbitrary code due to deserialization of untrusted data.
Marshaling, Unmarshaling
IBM FTM/RH OpenShift Remote Auth RCE via Quantity Validation
CVE-2026-17636
8.8 - High
- September 22, 2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to execute arbitrary code due to improper validation of a specified quantity.
Memory Corruption
IBM FTM HTTP Method Misconfiguration Permits Remote Unauthorized Actions
CVE-2026-17635
9.1 - Critical
- September 22, 2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to perform unauthorized actions due to improper configuration of HTTP method-based security constraints.
Missing Authentication for Critical Function
IBM FTM 4.0.6.0 Cleartext Data Transmission Vulnerability
CVE-2026-17620
5.3 - Medium
- September 22, 2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift 4.0.6.0 through 4.0.6.0.0.6.0 Refresh (Operator 4.4.6+20260807.081800)4.0.7.04.0.8.04.0.9.04.0.10.0 Interim Fix 064 IBM Financial Transaction Manager transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
Unprotected Transport of Credentials
FTM for OpenShift: Remote Unauth RCE & DoS via Improper Auth
CVE-2026-17618
7.3 - High
- September 22, 2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote unauthenticated attacker to view and modify sensitive information and cause a denial of service due to improper authorization.
AuthZ
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for IBM Financial Transaction Manager Ftmfor Redhat Openshift or by IBM? Click the Watch button to subscribe.