« Volver al listado

Redhat

Redhat Openshift: vulnerabilidades y CVE

Redhat Openshift tiene 198 vulnerabilidades publicadas, 55 de ellas en los últimos 12 meses. 18 son críticas y 2 figuran en el catálogo de explotación activa de CISA.

CVE198
Últimos 12 meses55
Críticas18
Explotadas activamente2

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

🔴 Explotadas activamente (CISA KEV)

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2023-44487Alta (7.5)100%⚠ Explotación activa10 oct 2023
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
CVE-2015-5317Alta (7.5)23%⚠ Explotación activa25 nov 2015
The Fingerprints pages in Jenkins before 1.638 and LTS before 1.625.2 might allow remote attackers to obtain sensitive job and build name information via a direct request.

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-19267Media (6.2)0.13%—23 sept 2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to missing authentication on the Business Rules Manager commands REST endpoint (`CommandsResource.java:31`). A local actor can invoke…
CVE-2026-19179Alta (8.2)0.30%—23 sept 2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to manipulate database queries due to improper neutralization of special elements in a boolean expression.
CVE-2026-19087Media (4.4)0.09%—23 sept 2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a local attacker to achieve privilege escalation within the container due to improper privilege management.
CVE-2026-18875Alta (7.3)0.22%—23 sept 2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to RAG poisoning via unauthenticated runbook upsert (CWE-74) in the FTM AI agent server (api.vectordb.runbooks.js:51). An unauthenticated…
CVE-2026-18872Crítica (9.3)0.19%—23 sept 2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to stored cross-site scripting (CWE-79) in the FTM UI NetworkAcknowledgement React component (NetworkAcknowledgement.jsx:42). A malicious actor…
CVE-2026-18505Media (5.4)0.15%—23 sept 2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to open redirect in the PMP `HostHeaderFilter` (`HostHeaderFilter.java:151`). An unauthenticated attacker can craft a request with a manipulated…
CVE-2026-18490Alta (8.8)0.25%—23 sept 2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to unauthenticated remote code execution via Java native deserialization on the PayDir Business Rules Manager RMI SSL endpoint…
CVE-2026-18185Alta (7.3)0.26%—23 sept 2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to access sensitive information and modify system configurations due to missing authentication for a critical function.
CVE-2026-18184Alta (7.4)0.22%—23 sept 2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive information due to an XML external entity (XXE) injection flaw.
CVE-2026-18181Alta (8.1)0.25%—23 sept 2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to bypass authentication and access sensitive information due to a hard-coded cryptographic key.
CVE-2026-18180Media (6.5)0.27%—23 sept 2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to obtain sensitive information due to SQL injection.
CVE-2026-18179Media (6.5)0.24%—23 sept 2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to clear active chat sessions due to improper authorization.
CVE-2026-18177Alta (7.1)0.18%—23 sept 2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute unauthorized payment actions due to missing authorization checks.
CVE-2026-18176Alta (7.4)0.13%—22 sept 2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive information due to cleartext transmission of sensitive information.
CVE-2026-18173Baja (3.7)0.24%—22 sept 2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive information due to improper enforcement of mutual TLS authentication.
CVE-2026-18172Alta (7.4)0.20%—22 sept 2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive information due to improper restriction of XML external entity references.
CVE-2026-18170Media (6.5)0.19%—22 sept 2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to cause a denial of service due to allocation of resources without limits or throttling.
CVE-2026-18169Crítica (9.9)0.53%—22 sept 2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to obtain sensitive information due to improper validation of symbolic links.
CVE-2026-18163Crítica (9.8)0.51%—22 sept 2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute arbitrary code due to improper deserialization of untrusted data.
CVE-2026-18162Crítica (9.8)0.48%—22 sept 2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute arbitrary code due to improper neutralization of user-controlled input within the new Function constructor.
CVE-2026-18161Media (4.3)0.20%—22 sept 2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to falsify transaction audit logs due to improper validation of a client-supplied HTTP header.
CVE-2026-18156Media (6.5)0.24%—22 sept 2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to bypass security controls by forging user identities due to improper authorization.
CVE-2026-18154Alta (8)0.17%—22 sept 2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive information due to the use of a hard-coded or predictable cryptographic key.
CVE-2026-18153Media (5.4)0.14%—22 sept 2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to obtain sensitive information and forge authentication tags due to the use of hard-coded cryptographic keys and…
CVE-2026-18152Alta (7.4)0.12%—22 sept 2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to forge validly-signed messages due to improper verification of cryptographic signatures.
CVE-2026-18137Alta (8.1)0.30%—22 sept 2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute arbitrary ESQL commands due to improper neutralization of special elements used in an ESQL command.
CVE-2026-18134Alta (7.5)0.13%—22 sept 2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive information due to cleartext transmission of sensitive information.
CVE-2026-18133Media (5.4)0.30%—22 sept 2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to modify server files due to path traversal.
CVE-2026-18132Media (6.5)0.21%—22 sept 2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to perform unauthorized payment mutation actions due to missing authorization.
CVE-2026-18131Alta (8.2)0.25%—22 sept 2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute arbitrary JavaScript in an authenticated user's browser due to improper neutralization of HTML input.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1210 Exploitation of Remote Services25
  2. T1190 Exploit Public-Facing Application14
  3. T1005 Data from Local System8
  4. T1068 Exploitation for Privilege Escalation8
  5. T1078 Valid Accounts6
  6. T1059 Command and Scripting Interpreter5

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Redhat