CVE-2026-93030
- EPSS 0.28%
- Veröffentlicht 25.09.2026 14:32:52
- Zuletzt bearbeitet 25.09.2026 16:17:29
FTM 4.x ALL could allow a remote authenticated attacker to obtain sensitive information due to an XML external entity injection flaw.
CVE-2026-19267
- EPSS 0.13%
- Veröffentlicht 23.09.2026 15:49:08
- Zuletzt bearbeitet 07.10.2026 13:02:57
IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to missing authentication on the Business Rules Manager commands REST endpoint (`CommandsResource.java:31`). A local actor can invoke unauthenticated commands to cause resourc...
CVE-2026-19179
- EPSS 0.3%
- Veröffentlicht 23.09.2026 15:48:33
- Zuletzt bearbeitet 07.10.2026 13:03:01
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to manipulate database queries due to improper neutralization of special elements in a boolean expression.
CVE-2026-19087
- EPSS 0.09%
- Veröffentlicht 23.09.2026 15:48:00
- Zuletzt bearbeitet 07.10.2026 13:03:04
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a local attacker to achieve privilege escalation within the container due to improper privilege management.
CVE-2026-18875
- EPSS 0.22%
- Veröffentlicht 23.09.2026 15:47:25
- Zuletzt bearbeitet 07.10.2026 13:03:07
IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to RAG poisoning via unauthenticated runbook upsert (CWE-74) in the FTM AI agent server (api.vectordb.runbooks.js:51). An unauthenticated attacker can insert malicious runbook...
CVE-2026-18872
- EPSS 0.19%
- Veröffentlicht 23.09.2026 15:46:42
- Zuletzt bearbeitet 07.10.2026 13:03:10
IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to stored cross-site scripting (CWE-79) in the FTM UI NetworkAcknowledgement React component (NetworkAcknowledgement.jsx:42). A malicious actor can inject script into stored n...
CVE-2026-18505
- EPSS 0.15%
- Veröffentlicht 23.09.2026 15:46:10
- Zuletzt bearbeitet 07.10.2026 13:03:16
IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to open redirect in the PMP `HostHeaderFilter` (`HostHeaderFilter.java:151`). An unauthenticated attacker can craft a request with a manipulated `Host` header to redirect auth...
CVE-2026-18490
- EPSS 0.25%
- Veröffentlicht 23.09.2026 15:45:29
- Zuletzt bearbeitet 07.10.2026 13:03:40
IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to unauthenticated remote code execution via Java native deserialization on the PayDir Business Rules Manager RMI SSL endpoint (BrmRMISSLServerSocketFactory.java:95, EP8). An ...
CVE-2026-18185
- EPSS 0.26%
- Veröffentlicht 23.09.2026 15:44:45
- Zuletzt bearbeitet 07.10.2026 13:03:42
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to access sensitive information and modify system configurations due to missing authentication for a critical function.
CVE-2026-18184
- EPSS 0.22%
- Veröffentlicht 23.09.2026 15:43:57
- Zuletzt bearbeitet 07.10.2026 13:03:45
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive information due to an XML external entity (XXE) injection flaw.