Where
AND
-Infinity
0

Vendor Risk Score

See how redhat compares to other vendors in security performance

View Risk Score →

Software

redhat enterprise linux
518
redhat enterprise linux server
312
redhat enterprise linux desktop
311
redhat enterprise linux workstation
298
redhat enterprise linux server aus
215
redhat enterprise linux server tus
175
redhat enterprise linux eus
142
redhat enterprise linux server eus
124
redhat openshift container platform
103
redhat linux
100
redhat jboss enterprise application platform
59
redhat enterprise linux for ibm z systems
45
redhat enterprise linux for power little endian
42
redhat enterprise linux for power little endian eus
42
redhat enterprise linux for ibm z systems eus
41
redhat openshift
38
redhat build of keycloak
35
redhat single sign-on
35
redhat virtualization
35
redhat enterprise linux server for power little endian update services for sap solutions
33
redhat virtualization host
32
redhat software collections
30
redhat satellite
28
redhat openstack
23
redhat enterprise linux for arm 64
21
redhat enterprise linux for arm 64 eus
21
redhat enterprise linux for real time
21
redhat linux advanced workstation
21
redhat codeready linux builder
18
redhat enterprise linux for real time for nfv
18
redhat jboss core services
18
redhat enterprise linux server update services for sap solutions
17
redhat hardened images
17
redhat enterprise linux update services for sap solutions
16
redhat fedora core
16
redhat openshift service mesh
16
redhat quay
16
redhat enterprise linux aus
15
redhat codeready linux builder for ibm z systems eus
13
redhat codeready linux builder for power little endian eus
13
redhat enterprise linux for power big endian
13
redhat keycloak
13
redhat codeready linux builder eus
12
redhat codeready linux builder for arm64 eus
12
redhat enterprise linux hpc node
12
redhat jboss enterprise web server
12
redhat undertow
12
redhat enterprise linux for real time for nfv tus
11
redhat enterprise linux for real time tus
11
redhat enterprise mrg
11
Severity
7.4
AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

IBM Financial Transaction Manager (FTM) could allow a remote attacker to obtain sensitive information due to cleartext transmission of sensitive information.

1 / 2
Source: IBM
First published (updated )
Severity
7.6
AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H

IBM Financial Transaction Manager (FTM) could allow a remote attacker to cause a denial of service due to the improper use of reflection with externally controlled input.

1 / 2
Source: IBM
First published (updated )
Severity
8.2
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L

IBM Financial Transaction Manager (FTM) could allow a remote attacker to manipulate database queries due to improper neutralization of special elements in a boolean expression.

1 / 2
Source: IBM
First published (updated )
Severity
8
AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N

IBM Financial Transaction Manager (FTM) could allow a remote attacker to obtain sensitive information due to the use of a hard-coded or predictable cryptographic key.

1 / 2
Source: IBM
First published (updated )
Severity
7.1
AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L

IBM Financial Transaction Manager (FTM) could allow a remote attacker to execute unauthorized payment actions due to missing authorization checks.

1 / 2
Source: IBM
First published (updated )
Severity
7.9
SSRF
AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N

IBM Financial Transaction Manager (FTM) could allow a local attacker to obtain sensitive information and trigger unauthorized actions due to server-side request forgery.

1 / 2
Source: IBM
First published (updated )
Severity
8.8
AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

IBM Financial Transaction Manager (FTM) could allow a local attacker to gain unauthorized access to sensitive information and modify transaction data due to the use of hard-coded credentials.

1 / 2
Source: IBM
First published (updated )
Severity
7.4
XEE
AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

IBM Financial Transaction Manager (FTM) could allow a remote attacker to obtain sensitive information due to improper restriction of XML external entity references.

1 / 2
Source: IBM
First published (updated )
Severity
7.5
Path Traversal
AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

IBM Financial Transaction Manager (FTM) could allow a remote attacker to read arbitrary files due to improper path canonicalization.

1 / 2
Source: IBM
First published (updated )
Severity
7.5
AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

IBM Financial Transaction Manager (FTM) could allow a remote attacker to obtain sensitive information due to cleartext transmission of sensitive information.

1 / 2
Source: IBM
First published (updated )
Severity
8.8
AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

IBM Financial Transaction Manager (FTM) could allow a local attacker to obtain sensitive information and perform unauthorized actions due to insufficiently protected credentials.

1 / 2
Source: IBM
First published (updated )
Severity
8.8
AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

IBM Financial Transaction Manager (FTM) could allow a local attacker to execute arbitrary commands due to the inclusion of functionality from an untrusted control sphere.

1 / 2
Source: IBM
First published (updated )
Severity
8.5
XEE
AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N

IBM Financial Transaction Manager (FTM) could allow a remote authenticated attacker to obtain sensitive information due to improper restriction of XML external entity references.

1 / 2
Source: IBM
First published (updated )
Severity
8.2
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L

IBM Financial Transaction Manager (FTM) could allow a remote attacker to perform unauthorized actions due to improper authentication and missing authorization.

1 / 2
Source: IBM
First published (updated )
Severity
7.3
AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

IBM Financial Transaction Manager (FTM) could allow a remote attacker to access sensitive information and modify system configurations due to missing authentication for a critical function.

1 / 2
Source: IBM
First published (updated )
Severity
8.1
SQL Injection
AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

IBM Financial Transaction Manager (FTM) could allow a remote attacker to execute arbitrary ESQL commands due to improper neutralization of special elements used in an ESQL command.

1 / 2
Source: IBM
First published (updated )
Severity
7.1
AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

IBM Financial Transaction Manager (FTM) could allow a remote authenticated attacker to obtain sensitive information and forge authentication tags due to the use of hard-coded cryptographic keys and initialization vectors.

1 / 2
Source: IBM
First published (updated )
Severity
7.4
XEE
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

IBM Financial Transaction Manager (FTM) could allow a remote attacker to obtain sensitive information due to an XML external entity (XXE) injection flaw.

1 / 2
Source: IBM
First published (updated )
Severity
7.3
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

IBM Financial Transaction Manager (FTM) 4.x is vulnerable to RAG poisoning via unauthenticated runbook upsert (CWE-74) in the FTM AI agent server (api.vectordb.runbooks.js:51). An unauthenticated attacker can insert malicious runbook content into the agent's vector database to steer AI-driven MCP tool calls, potentially triggering unauthorized payment actions or exfiltrating payment data.

1 / 2
Source: IBM
First published (updated )
Severity
8.8
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

IBM Financial Transaction Manager (FTM) 4.x is vulnerable to unauthenticated remote code execution via Java native deserialization on the PayDir Business Rules Manager RMI SSL endpoint (BrmRMISSLServerSocketFactory.java:95, EP8). An adjacent-network attacker can deliver a crafted serialized payload to achieve arbitrary code execution, exposing all PayDir credentials and enabling manipulation of payment business rules.

1 / 2
Source: IBM
First published (updated )
Severity
7.5
AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N

FTM 4.x ALL could allow a remote authenticated attacker to obtain sensitive information due to an XML external entity injection flaw.

1 / 2
Source: IBM
First published (updated )
Severity
8.8
Buffer Overflow
AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H

IBM Financial Transaction Manager (FTM) could allow a remote authenticated attacker to execute arbitrary code due to a buffer overflow.

1 / 2
Source: IBM
First published (updated )
Severity
8.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

IBM Financial Transaction Manager (FTM) could allow a remote attacker to bypass authentication and access sensitive information due to a hard-coded cryptographic key.

1 / 2
Source: IBM
First published (updated )
Severity
8.8
AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow an adjacent-network attacker to execute arbitrary code due to deserialization of untrusted data.

1 / 2
Source: MITRE
First published (updated )
Severity
8.8
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

IBM Financial Transaction Manager (FTM) could allow a remote authenticated attacker to execute arbitrary code due to improper validation of a specified quantity.

1 / 2
Source: IBM
First published (updated )
Severity
8.2
XSS
AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:H/A:N

IBM Financial Transaction Manager (FTM) could allow a remote attacker to execute arbitrary JavaScript in an authenticated user's browser due to improper neutralization of HTML input.

1 / 2
Source: IBM
First published (updated )
Severity
7.5
AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

A flaw was found in Red Hat Quay's Stripe billing webhook handler. The /webhooks/stripe endpoint at endpoints/webhooks.py accepts incoming JSON requests without validating the Stripe-Signature header, allowing an unauthenticated attacker to forge billing events. The endpoint is registered unconditionally, even when FEATUREBILLING is disabled. An attacker can forge charge.succeeded events to reset a namespace's build quota to the server-configured maximum and trigger unsolicited billing emails (invoice, payment-failed, subscription-change) to namespace administrators. The checkout.session.completed path calls stripe.SetupIntent.retrieve with attacker-controlled IDs, but subsequent mutations use values from Stripe's response rather than the attacker's payload. Impact is Medium-High for quay.io deployments with real Stripe integration and Low for self-hosted defaults using FakeStripe.

1 / 2
Source: Red Hat
First published (updated )
Severity
7.5
AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

A flaw was found in Red Hat Quay's exported logs feature. An unauthenticated attacker with a valid file ID could download exported action logs without proper authorization. While file IDs are complex, they can be intercepted from plaintext email or webhook callbacks. This vulnerability leads to information disclosure, potentially exposing sensitive data such as usernames, email addresses, IP addresses, and action-specific metadata.

1 / 2
Source: MITRE
First published (updated )
Severity
7.1
SSRF
AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N

A flaw was found in Red Hat Quay. A user with FEATUREBUILDSUPPORT enabled and repository write access can exploit a Server-Side Request Forgery (SSRF) vulnerability within the build API. This allows the user to provide a malicious URL, causing the Quay builder to make requests to internal network addresses. Such an action could lead to the disclosure of sensitive internal information.

1 / 2
Source: MITRE
First published (updated )
Severity
8.2
Path Traversal
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L

A flaw was found in Red Hat Quay. When the SECURITYSCANNERV4PSK (pre-shared key) is not set, a remote unauthenticated attacker can send POST requests to the security scanner notification endpoint. This allows the attacker to flood the notification queue and inject path traversal characters into Clair API URL paths. The primary consequence is worker resource exhaustion and blind path manipulation on the configured Clair host, potentially leading to a denial of service.

1 / 2
Source: MITRE
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203