CVE-2026-18153
Received Received - Intake

IBM FTM for RedHat OpenShift Hard-Coded Cryptographic Keys Vulnerability

Vulnerability report for CVE-2026-18153, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-22

Last updated on: 2026-09-22

Assigner: IBM Corporation

Description

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to obtain sensitive information and forge authentication tags due to the use of hard-coded cryptographic keys and initialization vectors.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-22
Last Modified
2026-09-22
Generated
2026-09-23
AI Q&A
2026-09-23
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
ibm financial_transaction_manager *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-327 The product uses a broken or risky cryptographic algorithm or protocol.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

IBM Financial Transaction Manager (FTM) for RedHat OpenShift uses hard-coded cryptographic keys and initialization vectors. This flaw allows a remote authenticated attacker to obtain sensitive information and forge authentication tags, compromising data integrity and confidentiality.

Impact Analysis

An attacker could exploit this to access sensitive data or manipulate transactions. This may lead to financial loss, reputational damage, or unauthorized access to critical systems if you use IBM FTM for RedHat OpenShift.

Compliance Impact

This vulnerability could violate compliance requirements such as GDPR (data protection) and HIPAA (healthcare data security) due to unauthorized data access and potential breaches of confidentiality and integrity.

Mitigation Strategies

Replace hard-coded cryptographic keys and initialization vectors with dynamically generated ones. Ensure all cryptographic operations use unique keys and vectors per session or transaction.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-18153. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart