CVE-2026-17644

8.8

IBM · Financial Transaction Manager (FTM) for RedHat OpenShift

IBM Financial Transaction Manager for RedHat OpenShift contains hard-coded credentials, allowing local attackers to access sensitive information and modify transaction data.

Executive summary

A vulnerability in IBM Financial Transaction Manager for RedHat OpenShift allows local attackers to gain unauthorized access and modify transaction data due to hard-coded credentials.

Vulnerability

The software utilizes hard-coded credentials, a weakness categorized as CWE-798. This vulnerability allows a local authenticated attacker with low privileges to bypass security controls and interact with sensitive financial transaction data.

Business impact

The presence of hard-coded credentials presents a significant risk to the integrity and confidentiality of financial operations. With a CVSS score of 8.8, this vulnerability is considered High, as it enables unauthorized modification of transaction data, which could lead to severe financial loss, regulatory non-compliance, and damage to organizational reputation.

Remediation

Immediate Action: Update your IBM Financial Transaction Manager for RedHat OpenShift deployment to version 4.0.11.0 immediately as specified in the vendor security advisory.

Proactive Monitoring: Review system access logs for unauthorized attempts to access management interfaces or database configurations that may be associated with the hard-coded credentials.

Compensating Controls: Ensure that access to the underlying RedHat OpenShift environment is strictly restricted to authorized personnel using role-based access control (RBAC) to limit the impact of local exploitation.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the critical nature of financial transaction systems, organizations must prioritize the application of the 4.0.11.0 patch provided by IBM. Failure to remediate this flaw leaves the environment susceptible to data tampering and unauthorized access by local actors. Please verify the installation of the update across all affected clusters to ensure full coverage.

More IBM CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources