CVE-2026-18137: IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities
IBM Financial Transaction Manager (FTM) could allow a remote attacker to execute arbitrary ESQL commands due to improper neutralization of special elements used in an ESQL command.
Other sources
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute arbitrary ESQL commands due to improper neutralization of special elements used in an ESQL command.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Financial Transaction Manager (FTM) for Red Hat OpenShiftto a version that resolves this vulnerability.Fixed in 4.0.11.0
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The issue is described as remotely exploitable. The available information does not specify any authentication, privileges, or other preconditions required by an attacker.
Which deployment is identified as affected?
The affected software identified in the available data is IBM Financial Transaction Manager for RedHat OpenShift. No affected versions, configurations, or fixed versions are provided.
How can I determine whether my environment is affected?
Verify whether you deploy IBM Financial Transaction Manager for RedHat OpenShift and consult the referenced IBM support advisory for product-specific applicability and remediation details. The available data does not provide version or configuration criteria for determining exposure.