← Back to search

CVE-2026-18490

8.8 HIGH

Published 2026-09-23 · Updated 2026-09-23

AI risk analysis

Summary
The flaw allows unauthenticated remote code execution via Java native deserialization on the PayDir Business Rules Manager RMI SSL endpoint, posing a significant security risk.
Exploitability
Exploitation requires delivery of a crafted serialized payload to the PayDir Business Rules Manager RMI SSL endpoint, making it moderately difficult. An adjacent-network attacker can exploit this vulnerability.
Blast radius
If exploited, this vulnerability could expose all PayDir credentials and enable manipulation of payment business rules, leading to severe financial and operational impacts.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Disable the PayDir Business Rules Manager RMI SSL endpoint or upgrade to the latest version of IBM Financial Transaction Manager (FTM) for RedHat OpenShift, specifically version 2.590 or later.
rceunauthjavarmisssl

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to unauthenticated remote code execution via Java native deserialization on the PayDir Business Rules Manager RMI SSL endpoint (BrmRMISSLServerSocketFactory.java:95, EP8). An adjacent-network attacker can deliver a crafted serialized payload to achieve arbitrary code execution, exposing all PayDir credentials and enabling manipulation of payment business rules.

CVSS vector

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-502

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.