CyberRota Analysis
AI-GeneratedIBM Financial Transaction Manager for RedHat OpenShift is susceptible to RAG poisoning due to an unauthenticated runbook upsert vulnerability in the AI agent server. This flaw allows an attacker to insert malicious content into the vector database, which could lead to unauthorized payment actions or the exfiltration of sensitive payment data. Organizations utilizing this product should prioritize patching this vulnerability to mitigate the risk of financial fraud and data breaches.
Original NVD Description
IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to RAG poisoning via unauthenticated runbook upsert (CWE-74) in the FTM AI agent server (api.vectordb.runbooks.js:51). An unauthenticated attacker can insert malicious runbook content into the agent's vector database to steer AI-driven MCP tool calls, potentially triggering unauthorized payment actions or exfiltrating payment data.
Related CVEs
Other vulnerabilities affecting the same vendor(s)