CVE-2026-18152: IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities
FTM 4.x ALL could allow a remote authenticated attacker to obtain sensitive information due to an XML external entity injection flaw.
Other sources
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to forge validly-signed messages due to improper verification of cryptographic signatures.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Financial Transaction Manager (FTM) for RedHat OpenShiftto a version that resolves this vulnerability.Fixed in 4.0.11.0
Event History
Frequently Asked Questions
Who can exploit this issue?
A remote attacker must be authenticated to exploit the XML external entity injection flaw.
What is the impact of successful exploitation?
Successful exploitation could allow an authenticated remote attacker to obtain sensitive information.
Which deployments are identified as affected?
The affected software is IBM Financial Transaction Manager for RedHat OpenShift, with FTM 4.x identified as affected.