CVE-2026-77874: IBM Enterprise Build of Quarkus is affected by multiple vulnerabilities
IBM Enterprise Build of Quarkus 3.27.1 through 3.27.5.SP1, and 3.33.1 through 3.33.3.SP1 is vulnerable to SQL injection. A remote unauthenticated attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.
Other sources
IBM Hibernate is vulnerable to SQL injection. A remote unauthenticated attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Enterprise Build of Quarkusto a version that resolves this vulnerability.Fixed in 3.27.5.SP2 - Upgrade
Upgrade
IBM Enterprise Build of Quarkusto a version that resolves this vulnerability.Fixed in 3.33.3.SP2
Event History
Frequently Asked Questions
Which releases are affected?
Affected releases are IBM Enterprise Build of Quarkus 3.27.1 through 3.27.5.SP1, and 3.33.1 through 3.33.3.SP1.
Does exploiting this issue require authentication or user interaction?
No. The vulnerability can be exploited remotely by an unauthenticated attacker, and no user interaction is required.
What could an attacker do after successful exploitation?
An attacker could send specially crafted SQL statements to view, add, modify, or delete information in the back-end database.