CVE-2026-18490: IBM Financial Transaction Manager (FTM) for RedHat OpenShift vulnerability
IBM Financial Transaction Manager (FTM) 4.x is vulnerable to unauthenticated remote code execution via Java native deserialization on the PayDir Business Rules Manager RMI SSL endpoint (BrmRMISSLServerSocketFactory.java:95, EP8). An adjacent-network attacker can deliver a crafted serialized payload to achieve arbitrary code execution, exposing all PayDir credentials and enabling manipulation of payment business rules.
Affected Software
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
IBM Financial Transaction Manager 4.x deployments using the PayDir Business Rules Manager RMI SSL endpoint are exposed. The provided data identifies IBM Financial Transaction Manager for Red Hat OpenShift as the affected software.
What access does an attacker need to exploit it?
An attacker needs adjacent-network access to reach the PayDir Business Rules Manager RMI SSL endpoint. Authentication is not required.
What could an attacker do after successful exploitation?
A crafted Java serialized payload can result in arbitrary remote code execution. This may expose PayDir credentials and allow manipulation of payment business rules.