Junglewise Threat Intelligence

CVE-2026-19267: IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to missing authentication on the Business Rules Manager commands

CVE-2026-19267 · Severity: medium · CVSS 6.2 · Published 2026-09-23

Executive brief

IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to missing authentication on the Business Rules Manager commands REST endpoint (`CommandsResource.java:31`). A local actor can invoke unauthenticated commands to cause resource exhaustionand halt business-rule management functions.

References