CVE-2026-18173: IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities
IBM Financial Transaction Manager (FTM) could allow a remote attacker to obtain sensitive information due to improper enforcement of mutual TLS authentication.
Other sources
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive information due to improper enforcement of mutual TLS authentication.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Financial Transaction Manager (FTM) for RedHat OpenShiftto a version that resolves this vulnerability.Fixed in 4.0.11.0
Event History
Frequently Asked Questions
What does an attacker need to exploit this issue?
The issue can be exploited remotely. The available information attributes it to improper enforcement of mutual TLS authentication, but does not specify any additional prerequisites or required credentials.
What is the potential impact?
A remote attacker could obtain sensitive information. The provided data does not identify the types of information exposed or the scope of affected deployments.