Executive brief
IBM Cloud Pak for Data System is an integrated data and analytics platform. A security vulnerability in the Cyclops component allows an authenticated user to perform SQL injection attacks. This could allow an attacker to unauthorizedly view, modify, or delete sensitive information stored in the platform's back-end database, potentially compromising data integrity.
Technical details
A SQL injection vulnerability (CWE-89) exists in the Cyclops component of IBM Cloud Pak for Data System versions 11.3.0.2 through 11.3.0.2-IF2. The flaw stems from improper neutralization of special elements used in SQL commands. A remote attacker with low-level privileges can exploit this by sending specially crafted SQL statements to the application. Successful exploitation allows the attacker to view, add, modify, or delete information within the back-end database. The issue is addressed in version 11.3.1.1 (Fix ID: 11.3.1.1-WS-ICPDS-CYCLOPS-fp278500).
Affected products
- IBM Cloud Pak for Data System - Cyclops 11.3.0.2 through 11.3.0.2-IF2
Timeline
- 2026-05-25: disclosed: Initial publication by IBM
- 2026-05-26: advisory: NVD publication date