Junglewise Threat Intelligence

CVE-2026-17619: IBM Platform RTM SQL injection in web interface

CVE-2026-17619 · Severity: high · CVSS 8.6 · Published 2026-09-18

Vendors: IBM.

Executive brief

IBM Platform RTM is a resource management system for distributed computing environments. The product accepts unvalidated SQL query input directly from its web interface, allowing a remote attacker to inject malicious SQL commands without authentication. An attacker could exploit this to view, modify, or delete data in the backend database, potentially exposing sensitive information or disrupting operations.

Technical details

IBM Platform RTM contains an SQL injection vulnerability (CWE-89) in its web interface where user-supplied SQL query input is not properly sanitized before execution. The vulnerability is remotely exploitable over the network with no authentication or user interaction required. An attacker can insert specially crafted SQL statements to execute arbitrary database commands, gaining unauthorized access to view, add, modify, or delete information in the backend database.

Affected products

  • IBM Platform RTM 10.2.0.15, 10.2.0.16

Timeline

  • 2026-09-16: disclosed
  • 2026-09-16: patched: Fix available in IBM Platform RTM 10.2 build 603092

References