CVE-2026-18162: IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities
IBM Financial Transaction Manager (FTM) could allow a remote attacker to execute arbitrary code due to improper neutralization of user-controlled input within the new Function constructor.
Other sources
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute arbitrary code due to improper neutralization of user-controlled input within the new Function constructor.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Financial Transaction Manager (FTM) for RedHat OpenShiftto a version that resolves this vulnerability.Fixed in 4.0.11.0
Event History
Frequently Asked Questions
Which deployments are identified as affected?
The available information identifies IBM Financial Transaction Manager for Red Hat OpenShift. It does not provide affected version ranges or configuration details.
What attacker access or interaction is required?
The issue is described as remotely exploitable through user-controlled input. The available information does not state whether authentication, specific privileges, or user interaction are required.