ZeroHour

CVE-2026-18658

moderate

Unauthenticated SQL Injection to RCE in IBM Operational Decision Manager

CVSS 3.1
9.8 critical
EPSS
<1%p36
Published
()
Modified
AI analysis

IBM Operational Decision Manager (ODM), an enterprise business-rules platform, contains a SQL injection vulnerability (CWE-89) in a component reachable over the network. An unauthenticated attacker can submit crafted input that is incorporated into SQL statements, gaining the ability to execute arbitrary SQL against the product's backend database. By leveraging database functionality to write files, the attacker can plant a web shell in the application web root and achieve remote code execution on the affected server. The flaw affects the listed ODM releases 8.11.0.1, 8.11.1.0, 8.12.0.1, 9.0.0.1, 9.5.0.0, 9.5.0.1, and 9.6.0.0, so any deployment running one of these versions is exposed. No public proof-of-concept, KEV listing, or confirmed in-the-wild exploitation is known at this time, and EPSS estimates only a 0.4% chance of exploitation within the next 30 days.

What to do: Apply the vendor fix for CVE-2026-18658 by upgrading each affected ODM release to the fixed or interim release specified in IBM's security bulletin. Until patched, restrict network access to the ODM application tier to trusted networks and users, since exploitation requires no authentication. As a compromise check, look for unexpected files or web shells in the application web root and review database logs for unusual or unexpected SQL statements.

Affected
IBM Operational Decision Manager8.11.0.1, 8.11.1.0, 8.12.0.1, 9.0.0.1, 9.5.0.0, 9.5.0.1, 9.6.0.0
Estimated exposure
moderatelikely thousands of enterprise installations worldwide (deployment-pattern estimate; no public install or scan counts) — No public install counts or internet-exposure scan data exist for this product, so the estimate is inferred from deployment patterns — on-premises business-rules servers run as small clusters inside large organizations in finance,…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

IBM Operational Decision Manager 9.6.0.0, 9.5.0.0, 8.11.1.0, 8.11.0.1, 8.12.0.1, 9.5.0.1, and 9.0.0.1 is vulnerable to SQL injection. An unauthenticated attacker can execute arbitrary SQL statements and leverage database functionality to write a web shell to the application web root, resulting in remote code execution.

Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.