AI description
CVE-2026-18162 is a vulnerability identified in IBM Financial Transaction Manager (FTM) for RedHat OpenShift. This flaw stems from the improper neutralization of user-controlled input within the JavaScript `Function` constructor. The vulnerability allows a remote attacker to inject and execute arbitrary code within the affected environment. This is due to the product constructing part of a code segment using external input without correctly neutralizing special elements that could alter the intended code's syntax or behavior.
- Description
- IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute arbitrary code due to improper neutralization of user-controlled input within the new Function constructor.
- Source
- psirt@us.ibm.com
- NVD status
- Awaiting Analysis
CVSS 3.1
- Type
- Secondary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
- psirt@us.ibm.com
- CWE-94
- Hype score
- Not currently trending
IBM FTM AI-agent RAG poisoning CVE-2026-18875 (CVSS 7.3): unauthenticated runbook upsert can steer MCP tool calls / payments. Also CVE-2026-18162 (CVSS 9.8). FTM 4.0.6–4.0.10 → upgrade 4.0.11.0. #Techage #Cyber #IBM #FinTech https://t.co/szVB2dBVfq
@techageone
26 Sept 2026
101 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
🚨 IBM FTM FOR OPENSHIFT: CRITICAL BULLETIN WITH UNAUTH RCE (CVE-2026-18163 / CVE-2026-18162) IBM published a Critical security bulletin for Financial Transaction Manager (FTM) for Red Hat OpenShift covering a large multi-CVE batch. Lead issues include: * CVE-2026-18163 —
@DailyDarkWeb
23 Sept 2026
6358 Impressions
0 Retweets
2 Likes
3 Bookmarks
0 Replies
0 Quotes
⚠️ Vulnerabilidades en productos IBM ❗ CVE-2026-18169 ❗ CVE-2026-18163 ❗ CVE-2026-18162 ➡️ Más info: https://t.co/Hbh42NJbI6 https://t.co/sMWOURdBAv
@CERTpy
23 Sept 2026
200 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes