VYPR

Financial Transaction Manager for RedHat OpenShift

by IBM

CVEs (3)

  • CVE-2026-18875HigSep 23, 2026
    risk 0.47cvss 7.3epss

    IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to RAG poisoning via unauthenticated runbook upsert (CWE-74) in the FTM AI agent server (api.vectordb.runbooks.js:51). An unauthenticated attacker can insert malicious runbook content into the agent's…

  • CVE-2026-19267MedSep 23, 2026
    risk 0.40cvss 6.2epss

    IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to missing authentication on the Business Rules Manager commands REST endpoint (`CommandsResource.java:31`). A local actor can invoke unauthenticated commands to cause resource exhaustionand halt…

  • CVE-2026-18505MedSep 23, 2026
    risk 0.35cvss 5.4epss

    IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to open redirect in the PMP `HostHeaderFilter` (`HostHeaderFilter.java:151`). An unauthenticated attacker can craft a request with a manipulated `Host` header to redirect authenticated operators to…