IBM Operational Decision Manager 9.6.0.0, 9.5.0.0, 8.11.1.0, 8.11.0.1, 8.12.0.1, 9.5.0.1, and 9.0.0.1 is vulnerable to SQL injection. An unauthenticated attacker can execute arbitrary SQL statements and leverage database functionality to write a web shell to the application web root, resulting in remote code execution.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7286196 |
|
History
Fri, 04 Sep 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM Operational Decision Manager 9.6.0.0, 9.5.0.0, 8.11.1.0, 8.11.0.1, 8.12.0.1, 9.5.0.1, and 9.0.0.1 is vulnerable to SQL injection. An unauthenticated attacker can execute arbitrary SQL statements and leverage database functionality to write a web shell to the application web root, resulting in remote code execution. | |
| Title | IBM Operational Decision Manager for Aug 2026 - Multiple CVEs addressed | |
| First Time appeared |
Ibm
Ibm operational Decision Manager |
|
| Weaknesses | CWE-89 | |
| CPEs | cpe:2.3:a:ibm:operational_decision_manager:8.11.0.1:*:*:*:*:*:*:* cpe:2.3:a:ibm:operational_decision_manager:8.11.1.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:operational_decision_manager:8.12.0.1:*:*:*:*:*:*:* cpe:2.3:a:ibm:operational_decision_manager:9.0.0.1:*:*:*:*:*:*:* cpe:2.3:a:ibm:operational_decision_manager:9.5.0.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:operational_decision_manager:9.5.0.1:*:*:*:*:*:*:* cpe:2.3:a:ibm:operational_decision_manager:9.6.0.0:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ibm
Ibm operational Decision Manager |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ibm
Published: 2026-09-04T16:10:18.743Z
Updated: 2026-09-04T16:10:18.743Z
Reserved: 2026-08-03T13:15:01.738Z
Link: CVE-2026-18658
No data.
Status : Awaiting Analysis
Published: 2026-09-04T16:17:21.133
Modified: 2026-09-08T14:17:08.940
Link: CVE-2026-18658
No data.