CVE-2026-18490

8.8

IBM · Financial Transaction Manager (FTM) for RedHat OpenShift

IBM Financial Transaction Manager (FTM) for RedHat OpenShift contains an unauthenticated remote code execution vulnerability via unsafe Java native deserialization.

Executive summary

An unauthenticated remote code execution vulnerability in IBM Financial Transaction Manager (FTM) for RedHat OpenShift allows adjacent attackers to compromise payment systems and credentials.

Vulnerability

The software fails to properly sanitize input during Java native deserialization on the PayDir Business Rules Manager RMI SSL endpoint (BrmRMISSLServerSocketFactory.java:95, EP8). This flaw allows an unauthenticated, adjacent-network attacker to execute arbitrary code with the privileges of the application.

Business impact

The ability for an attacker to achieve remote code execution poses a severe risk to financial integrity and data confidentiality. A successful exploit could lead to the theft of sensitive payment credentials and unauthorized manipulation of core business logic, potentially resulting in significant financial loss and regulatory non-compliance. With a CVSS score of 8.8, this high-severity vulnerability requires immediate attention to prevent total system compromise.

Remediation

Immediate Action: Update all affected instances of IBM Financial Transaction Manager (FTM) for RedHat OpenShift to version 4.0.11.0 as specified in the official vendor advisory.

Proactive Monitoring: Review system logs for unusual RMI traffic or unexpected process execution patterns originating from the PayDir Business Rules Manager endpoint.

Compensating Controls: Implement network segmentation to restrict access to the RMI SSL endpoint to trusted internal subnets only, effectively limiting the attack surface to authorized segments.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the potential for complete system compromise and the sensitivity of the financial data managed by this platform, organizations must prioritize the transition to version 4.0.11.0. Administrative teams should verify their current deployment versions immediately and schedule maintenance windows to apply the necessary patches, ensuring that the RMI endpoint is protected from unauthorized access during the remediation process.

More IBM CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources