CVE-2026-19267

6.2

IBM · Financial Transaction Manager (FTM) for RedHat OpenShift

IBM Financial Transaction Manager for RedHat OpenShift contains a missing authentication vulnerability in its Business Rules Manager REST endpoint, allowing local resource exhaustion.

Executive summary

A missing authentication flaw in the IBM Financial Transaction Manager for RedHat OpenShift allows a local actor to trigger resource exhaustion and disrupt business rule management.

Vulnerability

This vulnerability involves missing authentication on the Business Rules Manager commands REST endpoint, specifically within the CommandsResource.java file at line 31. An unauthenticated local attacker can invoke these commands to cause resource exhaustion, effectively halting critical business rule management functions.

Business impact

The exploitation of this vulnerability results in a denial of service for the business rule management functions of the FTM platform. While the CVSS score of 6.2 is categorized as medium, the impact on business continuity is significant for organizations relying on this software for financial transaction processing. The inability to manage business rules can lead to operational outages and potential disruptions in financial workflows.

Remediation

Immediate Action: Update the IBM Financial Transaction Manager for RedHat OpenShift deployment to version 4.0.11.0 as specified in the official vendor advisory.

Proactive Monitoring: Monitor system logs for unauthorized access attempts or suspicious activity targeting the Business Rules Manager REST API endpoints.

Compensating Controls: Ensure that local access to the server environment is strictly controlled and restricted to authorized personnel only to mitigate the risk posed by the local attack vector.

Exploitation status

Public Exploit Available: No (unknown)

Analyst recommendation

Organizations utilizing the affected versions of IBM Financial Transaction Manager for RedHat OpenShift must prioritize the update to version 4.0.11.0 to close the authentication gap. Given the potential for service disruption, administrators should perform this update during a scheduled maintenance window to ensure minimal impact on production financial services.

More IBM CVEs all →

History

  1. Analyst report written

Sources