Warning: SQL Injection in IBM watsonx Orchestrate Cartridge, Patch Immediately!
ID: 413c69c1-00c6-5759-a524-1ed100d0aca6
STIX ID: report--413c69c1-00c6-5759-a524-1ed100d0aca6
Feed Name: CCB Advisories Feed
**Executive summary:** A blind SQL injection vulnerability (CVE-2025-0165, CVSS 7.6) was disclosed in IBM watsonx Orchestrate Cartridge for IBM Cloud Pak for Data (affected versions 4.8.4–4.8.5 and 5.0.0–5.2.0); a low-privileged remote attacker could exploit it to view, add, modify, or delete data in the backend database, risking confidentiality and integrity. IBM recommends immediate upgrade to version 5.2.0.1 and enhanced monitoring and detection to mitigate potential intrusions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
