CVE-2026-17635: IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities
IBM Financial Transaction Manager (FTM) could allow a remote attacker to perform unauthorized actions due to improper configuration of HTTP method-based security constraints.
Other sources
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to perform unauthorized actions due to improper configuration of HTTP method-based security constraints.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Financial Transaction Manager (FTM) for Red Hat OpenShiftto a version that resolves this vulnerability.Fixed in 4.0.11.0
Event History
Frequently Asked Questions
Who can exploit this issue?
The vulnerability is remotely exploitable and requires no privileges or user interaction, according to the supplied severity vector. An attacker able to reach the affected FTM deployment may be able to perform unauthorized actions.
What security impact is indicated?
The supplied vector rates confidentiality and integrity impact as high, while availability impact is listed as none. The reported issue involves improperly configured HTTP method-based security constraints.