Description
IBM Platform RTM is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.
Published: 2026-09-18
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Database Compromise
Action: Immediate Patch
AI Analysis

Impact

The vulnerability allows a remote attacker to inject specially crafted SQL statements into the Platform RTM application, enabling the attacker to view, add, modify, or delete records in the back‑end database. This can lead to unauthorized data disclosure, unauthorized data modification, or removal of critical data, directly compromising the confidentiality and integrity of the system's data store.

Affected Systems

IBM Platform RTM, including version 10.2.0.15 and earlier releases. The vendor has released an update—build 603092—that resolves the issue but the original vulnerable versions remain at risk.

Risk and Exploitability

With a CVSS score of 8.6, the vulnerability is considered High. Although EPSS data is unavailable, the lack of a listed KEV record suggests that there are no known widespread exploit scripts; however, the attack vector is clearly remote, requiring an attacker to send malicious input over the network to a vulnerable endpoint. The impact is significant, and because the flaw involves SQL injection—a common vector—operators should treat the risk as high until the update is applied.

Generated by OpenCVE AI on September 19, 2026 at 10:45 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing this vulnerability now by upgrading to IBM Platform RTM 10.2 build 603092 available from IBM Fix Central


OpenCVE Recommended Actions

  • Apply the IBM Fix Central update 603092 to IBM Platform RTM immediately.
  • Reduce the attack surface by limiting or removing external network access to any interfaces that accept user input and interact with the database.
  • Implement or enforce parameterized queries and input validation at the application level to prevent malicious SQL from being executed on the database.

Generated by OpenCVE AI on September 19, 2026 at 10:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description IBM Platform RTM is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.
Title The IBM Platform RTM is affected by an SQL injection vulnerability
First Time appeared Ibm
Ibm spectrum Lsf Ibm Platform Rtm
Weaknesses CWE-89
CPEs cpe:2.3:a:ibm:spectrum_lsf_ibm_platform_rtm:10.2.0.15:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm spectrum Lsf Ibm Platform Rtm
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L'}


Subscriptions

Ibm Spectrum Lsf Ibm Platform Rtm
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-19T14:11:41.357Z

Reserved: 2026-07-27T20:34:52.483Z

Link: CVE-2026-17619

cve-icon Vulnrichment

Updated: 2026-09-19T14:07:47.386Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T20:17:10.077

Modified: 2026-09-22T19:32:25.730

Link: CVE-2026-17619

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T01:00:11Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')