Stored Cross-Site Scripting in IBM Financial Transaction Manager for RedHat OpenShift
CVE-2026-18872

9.3CRITICAL

Key Information:

Vendor

IBM

Vendor
CVE Published:
23 September 2026

What is CVE-2026-18872?

IBM Financial Transaction Manager for RedHat OpenShift is susceptible to a stored cross-site scripting vulnerability within the NetworkAcknowledgement React component. This flaw allows an attacker to inject malicious scripts into the stored network acknowledgement data. When authenticated operators view this data, the script executes in their browsers, which can lead to session hijacking and the potential for unauthorized actions related to payment processing.

Affected Version(s)

Financial Transaction Manager (FTM) for RedHat OpenShift 4.0.6.0 <= 4.0.10.0

References

CVSS V3.1

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.