logo

Warning: SQL Injection in IBM watsonx Orchestrate Cartridge, Patch Immediately!

ID: 413c69c1-00c6-5759-a524-1ed100d0aca6

STIX ID: report--413c69c1-00c6-5759-a524-1ed100d0aca6

Feed Name: CCB Advisories Feed

Threat Score
72/100

Date Published: 2025-09-01

Date Updated: 2026-07-24

...
...

**Executive summary:** A blind SQL injection vulnerability (CVE-2025-0165, CVSS 7.6) was disclosed in IBM watsonx Orchestrate Cartridge for IBM Cloud Pak for Data (affected versions 4.8.4–4.8.5 and 5.0.0–5.2.0); a low-privileged remote attacker could exploit it to view, add, modify, or delete data in the backend database, risking confidentiality and integrity. IBM recommends immediate upgrade to version 5.2.0.1 and enhanced monitoring and detection to mitigate potential intrusions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.