Impact
IBM Operational Decision Manager is vulnerable to unauthenticated SQL injection that enables an attacker to execute arbitrary SQL statements and write a web shell to the application’s web root, leading to remote code execution.
Affected Systems
IBM Operational Decision Manager versions 8.11.0.1, 8.11.1.0, 8.12.0.1, 9.0.0.1, 9.5.0.0, 9.5.0.1, and 9.6.0.0 are affected. The vulnerability can be triggered by unauthenticated requests that provide unvalidated input. Based on the description, it is inferred that these versions expose a publicly accessible interface that allows the injection payload to be transmitted.
Risk and Exploitability
The vulnerability carries a CVSS score of 9.8, indicating critical severity. The EPSS score is not available, but an unauthenticated attacker can reach the vulnerable code directly via web requests, making exploitation highly likely if the application is accessible from the internet. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment