Impact
IBM Enterprise Build of Quarkus versions 3.27.1 through 3.27.5.SP1 and 3.33.1 through 3.33.3.SP1 contain a SQL injection flaw that permits a remote, unauthenticated attacker to inject crafted SQL statements. The flaw can allow the attacker to view, add, modify, or delete data in the back‑end database, compromising confidentiality, integrity, and potentially availability of the application data.
Affected Systems
Affected systems are IBM Enterprise Build of Quarkus, specifically versions 3.27.1 to 3.27.5.SP1 and 3.33.1 to 3.33.3.SP1. Upgrading to 3.27.5.SP2 or 3.33.3.SP2 removes the vulnerability.
Risk and Exploitability
The CVSS score is 8.6, indicating a high severity vulnerability. No EPSS score is available, and it is not listed in the CISA KEV catalog. The attack vector is remote and unauthenticated, requiring the attacker to send specially crafted SQL payloads to the application’s exposed endpoints that interact with the database. Once exploited, the attacker can manipulate persistent data, leading to data loss, unauthorized disclosure, or service disruption.
OpenCVE Enrichment