CVE-2026-18137
8.1IBM · Financial Transaction Manager (FTM) for RedHat OpenShift
A remote SQL injection vulnerability in IBM Financial Transaction Manager for RedHat OpenShift allows unauthenticated attackers to execute arbitrary ESQL commands via improper input neutralization.
Executive summary
A critical SQL injection vulnerability in IBM Financial Transaction Manager for RedHat OpenShift allows remote, unauthenticated attackers to execute arbitrary commands and compromise financial data integrity.
Vulnerability
This is an improper neutralization of special elements used in an SQL command (CWE-89) that permits an unauthenticated remote attacker to inject and execute arbitrary ESQL commands.
Business impact
The ability to execute arbitrary SQL commands poses a severe risk to the confidentiality, integrity, and availability of sensitive financial transaction data. Given the CVSS score of 8.1, this high-severity flaw could lead to full database compromise, unauthorized modification of transaction records, or total service disruption, resulting in significant regulatory and reputational damage.
Remediation
Immediate Action: Update your IBM Financial Transaction Manager for RedHat OpenShift deployment to version 4.0.11.0 or later as specified by the vendor security bulletin.
Proactive Monitoring: Review database access logs for unusual query patterns or syntax errors that suggest injection attempts, and monitor transaction processing services for unexpected behavior.
Compensating Controls: Deploy a Web Application Firewall (WAF) with strict SQL injection protection rules to inspect incoming traffic and block malformed ESQL commands until the update can be applied.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Due to the nature of the software, which handles sensitive financial transactions, this vulnerability must be treated with high priority. Organizations should schedule the transition to version 4.0.11.0 immediately to eliminate the underlying SQL injection flaw and protect the integrity of the financial environment.
More IBM CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief high section