PT-2025-35358 · Ibm · Watsonx Orchestrate Cartridge For Ibm Cloud Pak For Data

CVE-2025-0165

·

Published

2025-08-30

·

Updated

2025-12-18

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions IBM watsonx Orchestrate Cartridge for IBM Cloud Pak for Data versions 4.8.4 through 5.2.0
Description IBM watsonx Orchestrate is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, potentially allowing them to view, add, modify, or delete information in the back-end database.
Recommendations Upgrade to version 5.2.0.1 to resolve this issue.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-0165

Affected Products

Watsonx Orchestrate Cartridge For Ibm Cloud Pak For Data