CVE-2026-18658
9.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Summary
IBM Operational Decision Manager 9.6.0.0, 9.5.0.0, 8.11.1.0, 8.11.0.1, 8.12.0.1, 9.5.0.1, and 9.0.0.1 is vulnerable to SQL injection. An unauthenticated attacker can execute arbitrary SQL statements and leverage database functionality to write a web shell to the application web root, resulting in remote code execution.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| IBM | Operational Decision Manager | 9.6.0.0 | affected |
| IBM | Operational Decision Manager | 9.5.0.0 | affected |
| IBM | Operational Decision Manager | 8.11.1.0 | affected |
| IBM | Operational Decision Manager | 8.11.0.1 | affected |
| IBM | Operational Decision Manager | 8.12.0.1 | affected |
| IBM | Operational Decision Manager | 9.5.0.1 | affected |
| IBM | Operational Decision Manager | 9.0.0.1 | affected |
Weaknesses
- CWE-89: CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.