CVE-2025-0165: IBM Watsonx Orchestrate Cartridge For IBM Cloud Pak For Data
Critical severity, CVSS 9.8. EPSS: 0.4% chance of exploitation in the next 30 days.
IBM watsonx Orchestrate Cartridge for IBM Cloud Pak for Data 4.8.4, 4.8.5, and 5.0.0 through 5.2.0 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.
Affected products
- IBM Watsonx Orchestrate Cartridge For IBM Cloud Pak For Data: from 4.8.4, up to and including 4.8.5; from 5.0.0, before 5.2.0.1 (fixed in 5.2.0.1)
Published 2025-08-30. Last modified 2026-06-17.