PT-2026-97353 · Red Hat+1 · Openshift+1

CVE-2026-18490

·

Published

2026-09-23

·

Updated

2026-09-23

CVSS v3.1

8.8

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions IBM Financial Transaction Manager (FTM) for RedHat OpenShift (affected versions not specified)
Description An unauthenticated adjacent-network attacker can achieve remote code execution by delivering a crafted serialized payload to the PayDir Business Rules Manager RMI SSL endpoint. This issue stems from Java native deserialization, a process where data is converted back into an object, which can be exploited to execute arbitrary code. Successful exploitation allows the attacker to expose all PayDir credentials and manipulate payment business rules. The vulnerability is located in BrmRMISSLServerSocketFactory.java:95 (EP8).
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-18490

Affected Products

Ibm Financial Transaction Manager
Openshift