Back

CRITICAL

IBM watsonx Orchestrate Cartridge for IBM Cloud Pak for Data SQL injection

Published Aug 30, 2025

Description

IBM watsonx Orchestrate Cartridge for IBM Cloud Pak for Data 4.8.4, 4.8.5, and 5.0.0 through 5.2.0 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.

Affected products

Remediation

Vendor solution

IBM strongly recommends addressing the vulnerability now by upgrading to IBM watsonx Orchestrate Cartridge 5.2.0.1

https://www.ibm.com/docs/en/watsonx/watson-orchestrate/current?topic=installing-watsonx-orchestrate-premises

Weaknesses (1)

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner ibm
Published Aug 30, 2025
Updated Sep 2, 2025
Reserved Dec 31, 2024
CISA Vulnrichment
Updated Sep 2, 2025
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner n/a
Published n/a
Updated n/a
Exploited since n/a
Link n/a