Open Redirect Vulnerability in IBM Financial Transaction Manager on RedHat OpenShift
CVE-2026-18505
5.4MEDIUM
Key Information:
- Vendor
IBM
- Vendor
- CVE Published:
- 23 September 2026
What is CVE-2026-18505?
IBM Financial Transaction Manager for RedHat OpenShift is affected by a vulnerability that allows an unauthenticated attacker to exploit an open redirect in the PMP HostHeaderFilter. By manipulating the Host header in their requests, attackers can redirect authenticated users to malicious sites, which can lead to credential phishing attacks. This significant security risk emphasizes the need for prompt remediation and heightened awareness regarding user credentials.
Affected Version(s)
Financial Transaction Manager (FTM) for RedHat OpenShift 4.0.6.0 <= 4.0.10.0