CVE-2026-18180: SQL Injection
Published Sep 21, 2026
·Updated
IBM Financial Transaction Manager (FTM) could allow a remote authenticated attacker to obtain sensitive information due to SQL injection.
Affected Software
1 affected component
IBM Financial Transaction Manager (FTM) for RedHat OpenShift<=4.0.6.0 - 4.0.6.0 iFix6
4.0.6.0 iFix6 Refresh (Operator 4.4.6+20260807.081800)
4.0.7.0
4.0.8.0
4.0.9.0
4.0.10.0
Event History
Sep 21, 2026
CVE Published
via IBM·12:00 AM
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Frequently Asked Questions
1
Which deployments are in scope?
The affected product identified is IBM Financial Transaction Manager for Red Hat OpenShift.
2
What level of access is required to exploit this issue?
An attacker must be remote and authenticated. The provided information does not indicate that unauthenticated exploitation is possible.