PT-2026-97353 · Red Hat+1 · Openshift+1
CVE-2026-18490
·
Published
2026-09-23
·
Updated
2026-09-23
CVSS v3.1
8.8
High
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
IBM Financial Transaction Manager (FTM) for RedHat OpenShift (affected versions not specified)
Description
An unauthenticated adjacent-network attacker can achieve remote code execution by delivering a crafted serialized payload to the PayDir Business Rules Manager RMI SSL endpoint. This issue stems from Java native deserialization, a process where data is converted back into an object, which can be exploited to execute arbitrary code. Successful exploitation allows the attacker to expose all PayDir credentials and manipulate payment business rules. The vulnerability is located in
BrmRMISSLServerSocketFactory.java:95 (EP8).Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
RCE
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Financial Transaction Manager
Openshift