Description

There has been a severe vulnerability, CVE-2025-0165, found in IBM Watsonx Orchestrate Cartridge for Cloud Pak for Data that allows blind SQL injection attacks. The vulnerability has been found to impact versions 4.8.4 to 5.2 and leads to authenticated attackers injecting SQL statements of malicious intent because of a lack of input sanitization, which can lead to back-end data confidentiality, integrity, and availability compromised. This vulnerability is known as CWE-89 (Improper Neutralization of Special Elements in SQL Commands) and has severe implications for sensitive information as well as system security. Watsonx Orchestrate Cartridge enables automated processes and brings AI functionality to heterogeneous data sources. Should the system be exposed to untrusted users or external networks, systems impacted by this flaw can be exposed to unauthorized access, modification, or deletion of data. IBM has assigned a CVSS v3.1 base score of 7.6 to this flaw, which is an indication of high-severity risk that needs immediate fixing. To assist in minimizing the exposure, IBM has offered a fix within release 5.2.0.1 of the Orchestrate Cartridge. Impacted customers are recommended to back up the database and configuration, download the fix from IBM Fix Central, and install it within a planned maintenance window. After installation, organizations must test for known injection vectors and audit logs for suspicious activity. Use of web application firewalls (WAFs) and least-privilege database access policies should also be implemented to avoid additional risk. While IBM was quick to issue a patch, organizations need to act equally quickly to harden their environments and avoid possible data breaches or downtime due to this exploit.