CVE-2026-17637: IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow an adjacent-network attacker to execute arbitrary code due to deserialization of untrusted data.
Other sources
IBM Financial Transaction Manager could allow an adjacent-network attacker to execute arbitrary code due to deserialization of untrusted data.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Financial Transaction Manager (FTM) for RedHat OpenShiftto a version that resolves this vulnerability.Fixed in 4.0.11.0
Event History
Frequently Asked Questions
What level of access does an attacker need?
The attacker must be able to reach the target from an adjacent network. No privileges or user interaction are required.
What could successful exploitation allow?
Successful exploitation could allow arbitrary code execution. The supplied severity vector indicates high potential impact to confidentiality, integrity, and availability.
Can this information identify which deployed versions are affected or fixed?
No. The provided data identifies IBM Financial Transaction Manager for RedHat OpenShift but does not include affected or fixed version ranges.