Redhat
Redhat Openshift: vulnerabilidades y CVE
Redhat Openshift tiene 198 vulnerabilidades publicadas, 55 de ellas en los últimos 12 meses. 18 son críticas y 2 figuran en el catálogo de explotación activa de CISA.
CVE198
Últimos 12 meses55
Críticas18
Explotadas activamente2
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-44487 | Alta (7.5) | 100% | ⚠ Explotación activa | 10 oct 2023 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. |
| CVE-2015-5317 | Alta (7.5) | 23% | ⚠ Explotación activa | 25 nov 2015 | The Fingerprints pages in Jenkins before 1.638 and LTS before 1.625.2 might allow remote attackers to obtain sensitive job and build name information via a direct request. |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-19267 | Media (6.2) | 0.13% | — | 23 sept 2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to missing authentication on the Business Rules Manager commands REST endpoint (`CommandsResource.java:31`). A local actor can invoke… |
| CVE-2026-19179 | Alta (8.2) | 0.30% | — | 23 sept 2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to manipulate database queries due to improper neutralization of special elements in a boolean expression. |
| CVE-2026-19087 | Media (4.4) | 0.09% | — | 23 sept 2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a local attacker to achieve privilege escalation within the container due to improper privilege management. |
| CVE-2026-18875 | Alta (7.3) | 0.22% | — | 23 sept 2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to RAG poisoning via unauthenticated runbook upsert (CWE-74) in the FTM AI agent server (api.vectordb.runbooks.js:51). An unauthenticated… |
| CVE-2026-18872 | Crítica (9.3) | 0.19% | — | 23 sept 2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to stored cross-site scripting (CWE-79) in the FTM UI NetworkAcknowledgement React component (NetworkAcknowledgement.jsx:42). A malicious actor… |
| CVE-2026-18505 | Media (5.4) | 0.15% | — | 23 sept 2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to open redirect in the PMP `HostHeaderFilter` (`HostHeaderFilter.java:151`). An unauthenticated attacker can craft a request with a manipulated… |
| CVE-2026-18490 | Alta (8.8) | 0.25% | — | 23 sept 2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to unauthenticated remote code execution via Java native deserialization on the PayDir Business Rules Manager RMI SSL endpoint… |
| CVE-2026-18185 | Alta (7.3) | 0.26% | — | 23 sept 2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to access sensitive information and modify system configurations due to missing authentication for a critical function. |
| CVE-2026-18184 | Alta (7.4) | 0.22% | — | 23 sept 2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive information due to an XML external entity (XXE) injection flaw. |
| CVE-2026-18181 | Alta (8.1) | 0.25% | — | 23 sept 2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to bypass authentication and access sensitive information due to a hard-coded cryptographic key. |
| CVE-2026-18180 | Media (6.5) | 0.27% | — | 23 sept 2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to obtain sensitive information due to SQL injection. |
| CVE-2026-18179 | Media (6.5) | 0.24% | — | 23 sept 2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to clear active chat sessions due to improper authorization. |
| CVE-2026-18177 | Alta (7.1) | 0.18% | — | 23 sept 2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute unauthorized payment actions due to missing authorization checks. |
| CVE-2026-18176 | Alta (7.4) | 0.13% | — | 22 sept 2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive information due to cleartext transmission of sensitive information. |
| CVE-2026-18173 | Baja (3.7) | 0.24% | — | 22 sept 2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive information due to improper enforcement of mutual TLS authentication. |
| CVE-2026-18172 | Alta (7.4) | 0.20% | — | 22 sept 2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive information due to improper restriction of XML external entity references. |
| CVE-2026-18170 | Media (6.5) | 0.19% | — | 22 sept 2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to cause a denial of service due to allocation of resources without limits or throttling. |
| CVE-2026-18169 | Crítica (9.9) | 0.53% | — | 22 sept 2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to obtain sensitive information due to improper validation of symbolic links. |
| CVE-2026-18163 | Crítica (9.8) | 0.51% | — | 22 sept 2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute arbitrary code due to improper deserialization of untrusted data. |
| CVE-2026-18162 | Crítica (9.8) | 0.48% | — | 22 sept 2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute arbitrary code due to improper neutralization of user-controlled input within the new Function constructor. |
| CVE-2026-18161 | Media (4.3) | 0.20% | — | 22 sept 2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to falsify transaction audit logs due to improper validation of a client-supplied HTTP header. |
| CVE-2026-18156 | Media (6.5) | 0.24% | — | 22 sept 2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to bypass security controls by forging user identities due to improper authorization. |
| CVE-2026-18154 | Alta (8) | 0.17% | — | 22 sept 2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive information due to the use of a hard-coded or predictable cryptographic key. |
| CVE-2026-18153 | Media (5.4) | 0.14% | — | 22 sept 2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to obtain sensitive information and forge authentication tags due to the use of hard-coded cryptographic keys and… |
| CVE-2026-18152 | Alta (7.4) | 0.12% | — | 22 sept 2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to forge validly-signed messages due to improper verification of cryptographic signatures. |
| CVE-2026-18137 | Alta (8.1) | 0.30% | — | 22 sept 2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute arbitrary ESQL commands due to improper neutralization of special elements used in an ESQL command. |
| CVE-2026-18134 | Alta (7.5) | 0.13% | — | 22 sept 2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive information due to cleartext transmission of sensitive information. |
| CVE-2026-18133 | Media (5.4) | 0.30% | — | 22 sept 2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to modify server files due to path traversal. |
| CVE-2026-18132 | Media (6.5) | 0.21% | — | 22 sept 2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to perform unauthorized payment mutation actions due to missing authorization. |
| CVE-2026-18131 | Alta (8.2) | 0.25% | — | 22 sept 2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute arbitrary JavaScript in an authenticated user's browser due to improper neutralization of HTML input. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.
Otros productos de Redhat
Enterprise Linux · 1937Enterprise Linux Desktop · 1928Enterprise Linux Server · 1891Enterprise Linux Workstation · 1845Enterprise Linux Server AUS · 1059Enterprise Linux EUS · 787Enterprise Linux Server TUS · 768Enterprise Linux Server EUS · 622Openshift Container Platform · 328Jboss Enterprise Application Platform · 244Satellite · 238Linux · 230