CVE-2026-18172: IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities
IBM Financial Transaction Manager (FTM) could allow a remote attacker to obtain sensitive information due to improper restriction of XML external entity references.
Other sources
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive information due to improper restriction of XML external entity references.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Financial Transaction Manager (FTM) for RedHat OpenShiftto a version that resolves this vulnerability.Fixed in 4.0.11.0
Event History
Frequently Asked Questions
What would an attacker need to exploit this issue?
The issue is described as allowing a remote attacker to obtain sensitive information through improperly restricted XML external entity references. The available data does not specify the required endpoint, authentication level, or XML input path.
Are all FTM deployments affected, including default configurations?
The available information identifies IBM Financial Transaction Manager for RedHat OpenShift, but does not state which versions, configurations, or default deployments are affected.
How can I determine whether my environment is affected?
Confirm whether you run IBM Financial Transaction Manager for RedHat OpenShift and review the referenced IBM support advisory for affected-version and remediation details. The provided data does not include indicators of compromise or a detection method.