CVE-2026-17619

8.6

IBM · Platform RTM

IBM Platform RTM is vulnerable to SQL injection, allowing a remote unauthenticated attacker to manipulate backend database contents via crafted SQL statements.

Executive summary

A critical SQL injection vulnerability in IBM Platform RTM allows unauthenticated remote attackers to compromise backend database integrity and confidentiality.

Vulnerability

This flaw is classified as an improper neutralization of special elements used in an SQL command (CWE-89). It allows an unauthenticated remote attacker to inject arbitrary SQL queries into the application, resulting in potential unauthorized data modification or exfiltration.

Business impact

The ability for an unauthenticated attacker to read, modify, or delete database information poses a severe risk to data integrity and business continuity. With a CVSS score of 8.6, this high-severity vulnerability could lead to total database compromise, resulting in the loss of sensitive operational data or unauthorized access to administrative functions.

Remediation

Immediate Action: Upgrade to IBM Platform RTM 10.2 build 603092, which is available for download through the IBM Fix Central portal.

Proactive Monitoring: Review database access logs for unusual query patterns, particularly those containing SQL syntax characters or unexpected administrative commands.

Compensating Controls: Deploy a Web Application Firewall (WAF) with updated rulesets to inspect incoming traffic for SQL injection signatures and block suspicious requests targeting the Platform RTM interface.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the high CVSS score and the potential for unauthenticated database manipulation, this vulnerability should be prioritized for immediate remediation. Organizations should verify their current version of IBM Platform RTM and apply the specified patch immediately to prevent unauthorized data access or system compromise.

More IBM CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources