CVE-2026-17646: IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities
IBM Financial Transaction Manager (FTM) could allow a remote authenticated attacker to obtain sensitive information due to improper restriction of XML external entity references.
Other sources
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to obtain sensitive information due to improper restriction of XML external entity references.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Financial Transaction Manager (FTM) for Red Hat OpenShiftto a version that resolves this vulnerability.Fixed in 4.0.11.0
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The attacker must be remote and authenticated. The provided information does not indicate that unauthenticated users can exploit it.
What is the potential impact of successful exploitation?
A successful attacker could obtain sensitive information through improperly restricted XML external entity references.