Back Redpacketsecurity CVE Alert: CVE-2026-17619 – IBM – spectrum-lsf : IBM Platform RTM
IBM Platform RTM is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.
**Risk verdict:** High-risk exposure requiring urgent remediation where the management interface is internet-accessible; exploitation status, KEV inclusion and EPSS probability are not provided, so active-threat prioritisation cannot be confirmed.
**Why this matters:** An unauthenticated attacker may be able to extract sensitive operational data and alter or remove database records. This could expose cluster, job, user and configuration information, disrupt workload management, or provide a stepping stone into systems that trust the platform.
**Most likely attack path:** The network-reachable, low-complexity path requires no prior account and no victim interaction, making automated probing plausible. Scope is unchanged, so direct impact is centred on the application and its database; however, stolen credentials, altered jobs or harvested infrastructure details could support lateral movement.
**Who is most exposed:** Organisations publishing the RTM web service, placing it on broadly reachable administration networks, or allowing access from untrusted partner or user segments face the greatest risk. Large research, engineering and high-performance-computing environments may have particularly valuable scheduling and account data.
Review web, reverse-proxy and database logs for unusual parameters, errors or query patterns.
Alert on unauthenticated requests to administrative and reporting endpoints.
Investigate unexpected database reads, writes, schema errors or bulk exports.
Correlate RTM activity with new accounts, changed jobs and outbound connections.
Mitigation and prioritisation:
Apply IBM’s recommended fixed build promptly, after validating integrations and database backups.
Restrict access through VPN, allow-listing and administrative network segmentation.
Use a web application firewall or targeted query-filtering rules as a temporary control.
Rotate exposed credentials and review database permissions for least privilege.
Confirm KEV, SSVC and EPSS status before final queue placement.
A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.
If you like the site, please support us on Patreon or Buy Me A Coffee using the buttons below.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
