PT-2025-35358 · Ibm · Watsonx Orchestrate Cartridge For Ibm Cloud Pak For Data

Published

2025-08-30

·

Updated

2025-12-18

·

CVE-2025-0165

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions IBM watsonx Orchestrate Cartridge for IBM Cloud Pak for Data versions 4.8.4 through 5.2.0
Description IBM watsonx Orchestrate is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, potentially allowing them to view, add, modify, or delete information in the back-end database.
Recommendations Upgrade to version 5.2.0.1 to resolve this issue.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-0165

Affected Products

Watsonx Orchestrate Cartridge For Ibm Cloud Pak For Data