9.8
CVE-2026-18162
- EPSS 0.48%
- Veröffentlicht 22.09.2026 22:10:47
- Zuletzt bearbeitet 06.10.2026 21:05:30
- Erkennungen
IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute arbitrary code due to improper neutralization of user-controlled input within the new Function constructor.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Financial Transaction Manager SwPlatform - Version >= 4.0.7.0 < 4.0.11.0
Ibm ≫ Financial Transaction Manager Version 4.0.6.0 Update - SwPlatform -
Ibm ≫ Financial Transaction Manager Version 4.0.6.0 Update interim_fix_1 SwPlatform -
Ibm ≫ Financial Transaction Manager Version 4.0.6.0 Update interim_fix_2 SwPlatform -
Ibm ≫ Financial Transaction Manager Version 4.0.6.0 Update interim_fix_3 SwPlatform -
Ibm ≫ Financial Transaction Manager Version 4.0.6.0 Update interim_fix_4 SwPlatform -
Ibm ≫ Financial Transaction Manager Version 4.0.6.0 Update interim_fix_5 SwPlatform -
Ibm ≫ Financial Transaction Manager Version 4.0.6.0 Update interim_fix_6 SwPlatform -
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.48% | 0.386 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| IBM | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-94 Improper Control of Generation of Code ('Code Injection')
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
https://www.ibm.com/support/pages/node/7288641