Improper Mutual TLS Authentication in IBM Financial Transaction Manager for RedHat OpenShift
CVE-2026-18173

3.7LOW

Key Information:

Vendor

IBM

Vendor
CVE Published:
22 September 2026

What is CVE-2026-18173?

The IBM Financial Transaction Manager for RedHat OpenShift has a vulnerability that can let an unauthorized remote attacker access sensitive information due to inadequate enforcement of mutual TLS authentication protocols. This flaw may expose data, creating potential risks for organizations that rely on secure financial transactions. It is crucial for users to review and apply recommended patches to mitigate this risk and enhance their security posture.

Affected Version(s)

Financial Transaction Manager (FTM) for RedHat OpenShift 4.0.6.0 <= 4.0.6.0.0.6.0 Refresh (Operator 4.4.6+20260807.081800)4.0.7.04.0.8.04.0.9.04.0.10.0 Interim Fix 064

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.