CVE-2026-18156: IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities
IBM Financial Transaction Manager (FTM) could allow a remote authenticated attacker to bypass security controls by forging user identities due to improper authorization.
Other sources
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to bypass security controls by forging user identities due to improper authorization.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Financial Transaction Manager (FTM) for Red Hat OpenShiftto a version that resolves this vulnerability.Fixed in 4.0.11.0
Event History
Frequently Asked Questions
Who can exploit this issue?
A remote attacker who is already authenticated can exploit it. The vulnerability is in IBM Financial Transaction Manager for RedHat OpenShift.
What does exploitation allow?
An authenticated attacker may forge user identities and bypass security controls because of improper authorization.