CVE-2026-18169

9.9

IBM · Financial Transaction Manager (FTM) for RedHat OpenShift

IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to a path traversal flaw caused by improper symbolic link validation, allowing information disclosure or system compromise.

Executive summary

A remote authenticated attacker can exploit a path traversal vulnerability in IBM Financial Transaction Manager for RedHat OpenShift to achieve full system compromise and unauthorized sensitive data access.

Vulnerability

This vulnerability is a path traversal flaw (CWE-22) resulting from improper validation of symbolic links. It allows a remote attacker with low privileges (authenticated) to escape restricted directory boundaries, leading to potential remote code execution or data theft.

Business impact

The CVSS score of 9.9 categorizes this as a critical vulnerability, reflecting the potential for complete system compromise within a high-value financial transaction environment. Successful exploitation could lead to the exposure of sensitive financial records, unauthorized modification of transaction data, and significant operational downtime, posing a severe risk to corporate integrity and regulatory compliance.

Remediation

Immediate Action: Update IBM Financial Transaction Manager (FTM) for RedHat OpenShift to version 4.0.11.0 or later as specified in the official IBM security advisory.

Proactive Monitoring: Review system and application logs for unusual file access patterns or suspicious symbolic link creation requests that deviate from standard operational behavior.

Compensating Controls: Implement strict file system permissions and deploy a Web Application Firewall (WAF) to inspect and block requests containing path traversal sequences or malicious link injection attempts.

Exploitation status

Public Exploit Available: No — exploit_available unknown.

Analyst recommendation

Given the critical CVSS severity of 9.9, this vulnerability poses an immediate threat to the confidentiality, integrity, and availability of financial transaction systems. Security teams should prioritize the update to version 4.0.11.0 immediately, as the risk of unauthorized system-wide access is high for any environment where an attacker can authenticate to the platform.

More IBM CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief critical section

Sources