CVE-2026-17636: IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities
IBM Financial Transaction Manager (FTM) could allow a remote authenticated attacker to execute arbitrary code due to improper validation of a specified quantity.
Other sources
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to execute arbitrary code due to improper validation of a specified quantity.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Financial Transaction Manager (FTM) for RedHat OpenShiftto a version that resolves this vulnerability.Fixed in 4.0.11.0
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The attacker must be remotely authenticated. The provided information does not indicate that unauthenticated attackers can exploit it.
What is the potential impact if exploitation succeeds?
A successful attacker could execute arbitrary code on the affected IBM Financial Transaction Manager for RedHat OpenShift deployment.