{"id":"CVE-2026-18490","published":"2026-09-23T16:16:41.460","lastModified":"2026-09-23T20:17:10.633","description":"IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to unauthenticated remote code execution via Java native deserialization on the PayDir Business Rules Manager RMI SSL endpoint (BrmRMISSLServerSocketFactory.java:95, EP8). An adjacent-network attacker can deliver a crafted serialized payload to achieve arbitrary code execution, exposing all PayDir credentials and enabling manipulation of payment business rules.","cvssScore":8.8,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-502"],"vendors":[],"products":[],"references":[{"url":"https://www.ibm.com/support/pages/node/7288641","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The flaw allows unauthenticated remote code execution via Java native deserialization on the PayDir Business Rules Manager RMI SSL endpoint, posing a significant security risk.","exploitability":"Exploitation requires delivery of a crafted serialized payload to the PayDir Business Rules Manager RMI SSL endpoint, making it moderately difficult. An adjacent-network attacker can exploit this vulnerability.","blast_radius":"If exploited, this vulnerability could expose all PayDir credentials and enable manipulation of payment business rules, leading to severe financial and operational impacts.","remediation":"Disable the PayDir Business Rules Manager RMI SSL endpoint or upgrade to the latest version of IBM Financial Transaction Manager (FTM) for RedHat OpenShift, specifically version 2.590 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["rce","unauth","java","rmis","ssl"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-29T08:56:38.386Z"}}