CVE-2026-17646

8.5

IBM · Financial Transaction Manager (FTM) for RedHat OpenShift

IBM Financial Transaction Manager for RedHat OpenShift is vulnerable to an XML External Entity (XXE) injection flaw, allowing authenticated remote attackers to access sensitive information.

Executive summary

A remote authenticated attacker can exploit an XML External Entity vulnerability in IBM Financial Transaction Manager for RedHat OpenShift to gain unauthorized access to sensitive system data.

Vulnerability

This flaw involves the improper restriction of XML external entity references (CWE-611). An authenticated remote attacker can manipulate XML inputs to force the application to disclose sensitive files or interact with internal network resources.

Business impact

Successful exploitation poses a significant risk to data confidentiality, as attackers can exfiltrate sensitive financial or configuration data from the affected environment. Given the CVSS score of 8.5, this vulnerability is categorized as high severity, reflecting the potential for severe impact on organizational security and compliance postures.

Remediation

Immediate Action: Update all deployments of IBM Financial Transaction Manager for RedHat OpenShift to version 4.0.11.0 or later as specified in the official IBM security bulletin.

Proactive Monitoring: Monitor application access logs for unusual XML parsing requests or attempts to access unexpected local file paths.

Compensating Controls: Implement strict input validation and disable DTD processing within XML parsers if immediate patching is not feasible.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Organizations utilizing the affected IBM FTM software must prioritize the upgrade to version 4.0.11.0 to eliminate the XXE injection risk. Given the sensitive nature of financial transaction platforms, failure to patch this vulnerability could result in unauthorized disclosure of critical business data. Verify the installation of the patch immediately to ensure the environment is secured against this high-severity threat.

More IBM CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources