Missing Authentication in IBM Financial Transaction Manager for RedHat OpenShift
CVE-2026-19267

6.2MEDIUM

Key Information:

Vendor

IBM

Vendor
CVE Published:
23 September 2026

What is CVE-2026-19267?

IBM Financial Transaction Manager for RedHat OpenShift is susceptible to a flaw that lacks proper authentication checks on the REST endpoint for Business Rules Manager commands. This vulnerability allows a local actor to execute unauthenticated commands, which could lead to resource exhaustion and disrupt critical business-rule management operations. Organizations using this product should apply the necessary patches to mitigate potential impacts.

Affected Version(s)

Financial Transaction Manager (FTM) for RedHat OpenShift 4.0.6.0 <= 4.0.10.0

References

CVSS V3.1

Score:
6.2
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.