CVE-2026-18658

IBM Operational Decision Manager 9.6.0.0, 9.5.0.0, 8.11.1.0, 8.11.0.1, 8.12.0.1, 9.5.0.1, and 9.0.0.1 is vulnerable to SQL injection. An unauthenticated attacker can execute arbitrary SQL statements and leverage database functionality to write a web shell to the application web root, resulting in remote code execution.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-04 16:17

Updated : 2026-09-10 21:17


NVD link : CVE-2026-18658

Mitre link : CVE-2026-18658

CVE.ORG link : CVE-2026-18658


JSON object : View

Products Affected

No product.

CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')