CVE-2026-17618: IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities
IBM Financial Transaction Manager (FTM) could allow a remote unauthenticated attacker to view and modify sensitive information and cause a denial of service due to improper authorization.
Other sources
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote unauthenticated attacker to view and modify sensitive information and cause a denial of service due to improper authorization.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Financial Transaction Manager (FTM) for RedHat OpenShiftto a version that resolves this vulnerability.Fixed in 4.0.11.0
Event History
Frequently Asked Questions
Who can exploit this issue?
A remote attacker does not need to authenticate or interact with a user. The stated impact applies to IBM Financial Transaction Manager for Red Hat OpenShift.
What could a successful attacker do?
An attacker could view or modify sensitive information and cause a denial of service. The vulnerability is attributed to improper authorization.
Is a default deployment known to be affected?
The provided information does not state whether default configurations are affected or identify any required non-default configuration.