CVE-2026-18162
9.8IBM · Financial Transaction Manager (FTM) for RedHat OpenShift
IBM FTM for RedHat OpenShift contains a code injection vulnerability in the Function constructor, allowing unauthenticated remote attackers to execute arbitrary code.
Executive summary
A critical code injection vulnerability in IBM Financial Transaction Manager for RedHat OpenShift exposes systems to unauthenticated remote code execution.
Vulnerability
This vulnerability involves improper neutralization of user-controlled input within the new Function constructor (CWE-94), which allows an unauthenticated remote attacker to inject and execute arbitrary code on the underlying system.
Business impact
The CVSS score of 9.8 reflects the severity of this flaw, as it requires no authentication or user interaction to achieve full system compromise. Successful exploitation grants an attacker the ability to execute arbitrary commands, potentially leading to unauthorized data exfiltration, complete system takeover, and significant disruption to critical financial transaction processing services.
Remediation
Immediate Action: Update IBM Financial Transaction Manager (FTM) for RedHat OpenShift to version 4.0.11.0 as specified in the vendor security advisory.
Proactive Monitoring: Review system and application logs for suspicious activity, particularly involving unexpected process execution or unusual inbound traffic directed at FTM management endpoints.
Compensating Controls: Deploy Web Application Firewall (WAF) rules to inspect and sanitize incoming requests for code-injection patterns, though these should be considered temporary measures until the patch is applied.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the critical nature of this vulnerability and the potential for full system compromise, organizations should prioritize the deployment of the 4.0.11.0 update. Immediate patching is necessary to eliminate the risk of remote code execution and ensure the integrity of the financial transaction environment.
More IBM CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief critical section