XML External Entity Injection Vulnerability in IBM Financial Transaction Manager for RedHat OpenShift
CVE-2026-18184

7.4HIGH

Key Information:

Vendor

IBM

Vendor
CVE Published:
23 September 2026

What is CVE-2026-18184?

An XML external entity injection vulnerability exists in IBM Financial Transaction Manager for RedHat OpenShift that may allow a remote attacker to access sensitive information through crafted XML input. This risk arises from improper handling of XML input, which could enable external entities to be processed, potentially leading to data disclosure. Users are encouraged to review the vendor's advisory for mitigation measures and updates.

Affected Version(s)

Financial Transaction Manager (FTM) for RedHat OpenShift 4.0.6.0 <= 4.0.10.0

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.