AI analysis
IBM Financial Transaction Manager (FTM) for Red Hat OpenShift contains a stored cross-site scripting (XSS) vulnerability in the NetworkAcknowledgement React component. The flaw allows a malicious actor to inject script into network acknowledgement data, which then executes in the browsers of authenticated operators. This could enable session hijacking and unauthorized payment actions at the operator level. The vulnerability has a critical CVSS score of 9.3. No public proof-of-concept or known in-the-wild exploitation has been reported.
What to do: Upgrade IBM Financial Transaction Manager for Red Hat OpenShift to the latest available version. Monitor for any signs of unauthorized payment actions or session hijacking in operator accounts. Ensure input validation and output encoding are applied to all user-supplied data in the UI.
Affected
| IBM Financial Transaction Manager (FTM) for Red Hat OpenShift | — |
Estimated exposure
nicheNo basis for an estimate.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to stored cross-site scripting (CWE-79) in the FTM UI NetworkAcknowledgement React component (NetworkAcknowledgement.jsx:42). A malicious actor can inject script into stored network acknowledgement data that executes in authenticated operator browsers, enabling session hijacking and unauthorized operator-level payment actions.