Impact
The vulnerability allows a remote attacker to inject specially crafted SQL statements into the Platform RTM application, enabling the attacker to view, add, modify, or delete records in the back‑end database. This can lead to unauthorized data disclosure, unauthorized data modification, or removal of critical data, directly compromising the confidentiality and integrity of the system's data store.
Affected Systems
IBM Platform RTM, including version 10.2.0.15 and earlier releases. The vendor has released an update—build 603092—that resolves the issue but the original vulnerable versions remain at risk.
Risk and Exploitability
With a CVSS score of 8.6, the vulnerability is considered High. Although EPSS data is unavailable, the lack of a listed KEV record suggests that there are no known widespread exploit scripts; however, the attack vector is clearly remote, requiring an attacker to send malicious input over the network to a vulnerable endpoint. The impact is significant, and because the flaw involves SQL injection—a common vector—operators should treat the risk as high until the update is applied.
OpenCVE Enrichment