CVE-2026-18658: IBM Operational Decision Manager for Aug 2026 - Multiple CVEs addressed
IBM Operational Decision Manager 9.6.0.0, 9.5.0.0, 8.11.1.0, 8.11.0.1, 8.12.0.1, 9.5.0.1, and 9.0.0.1 is vulnerable to SQL injection. An unauthenticated attacker can execute arbitrary SQL statements and leverage database functionality to write a web shell to the application web root, resulting in remote code execution.
Other sources
IBM Operational Decision Manager is vulnerable to SQL injection. An unauthenticated attacker can execute arbitrary SQL statements and leverage database functionality to write a web shell to the application web root, resulting in remote code execution.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Operational Decision Managerto a version that resolves this vulnerability.Fixed in 9.6.0.0 - Upgrade
Upgrade
IBM Operational Decision Managerto a version that resolves this vulnerability.Fixed in 9.5.0.0 - Upgrade
Upgrade
IBM Operational Decision Managerto a version that resolves this vulnerability.Fixed in 8.11.1.0 - Upgrade
Upgrade
IBM Operational Decision Managerto a version that resolves this vulnerability.Fixed in 8.11.0.1 - Upgrade
Upgrade
IBM Operational Decision Managerto a version that resolves this vulnerability.Fixed in 8.12.0.1 - Upgrade
Upgrade
IBM Operational Decision Managerto a version that resolves this vulnerability.Fixed in 9.5.0.1 - Upgrade
Upgrade
IBM Operational Decision Managerto a version that resolves this vulnerability.Fixed in 9.0.0.1 - Upgrade
Upgrade
IBM Operational Decision Managerto a version that resolves this vulnerability.Patch Interim fix 004 - Upgrade
Upgrade
IBM Operational Decision Managerto a version that resolves this vulnerability.Patch Interim fix 017 - Upgrade
Upgrade
IBM Operational Decision Managerto a version that resolves this vulnerability.Patch Interim fix 029 - Upgrade
Upgrade
IBM Operational Decision Managerto a version that resolves this vulnerability.Patch Interim fix 043 - Upgrade
Upgrade
IBM Operational Decision Managerto a version that resolves this vulnerability.Patch Interim fix 059 - Upgrade
Upgrade
IBM Operational Decision Managerto a version that resolves this vulnerability.Patch Interim fix 060
Event History
Frequently Asked Questions
Which IBM Operational Decision Manager versions are affected?
The affected versions are 9.6.0.0, 9.5.0.0, 8.11.1.0, 8.11.0.1, 8.12.0.1, 9.5.0.1, and 9.0.0.1.
What access does an attacker need to exploit this issue?
An attacker does not need to authenticate or interact with a user. The vulnerability is network-accessible and has low attack complexity.
What is the potential result of successful exploitation?
An attacker can execute arbitrary SQL statements and use database functionality to write a web shell into the application web root. This can result in remote code execution with high impact to confidentiality, integrity, and availability.