CVE-2026-18505: IBM Financial Transaction Manager
Medium severity, CVSS 5.4. EPSS: 0.1% chance of exploitation in the next 30 days.
IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to open redirect in the PMP `HostHeaderFilter` (`HostHeaderFilter.java:151`). An unauthenticated attacker can craft a request with a manipulated `Host` header to redirect authenticated operators to attacker-controlled sites, enabling credential phishing.
Affected products
- IBM Financial Transaction Manager: from 4.0.7.0, before 4.0.11.0 (fixed in 4.0.11.0); version 4.0.6.0 only
Published 2026-09-23. Last modified 2026-10-07.