CVE-2026-19267: IBM Financial Transaction Manager (FTM) for RedHat OpenShift vulnerability
Published Sep 21, 2026
·Updated
IBM Financial Transaction Manager (FTM) 4.x is vulnerable to missing authentication on the Business Rules Manager commands REST endpoint (CommandsResource.java:31). A local actor can invoke unauthenticated commands to cause resource exhaustionand halt business-rule management functions
Affected Software
1 affected component
IBM Financial Transaction Manager (FTM) for RedHat OpenShift<=4.0.6.0 - 4.0.6.0 iFix6
4.0.6.0 iFix6 Refresh (Operator 4.4.6+20260807.081800)
4.0.7.0
4.0.8.0
4.0.9.0
4.0.10.0
Event History
Sep 21, 2026
CVE Published
via IBM·12:00 AM
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The issue is described as exploitable by a local actor. The affected REST endpoint permits unauthenticated command invocation.
2
What is the expected impact of successful exploitation?
An attacker can cause resource exhaustion and halt business-rule management functions.