IBM Operational Decision Manager (ODM) across multiple versions (9.6.0.0, 9.5.0.0, 8.11.1.0, 8.11.0.1, 8.12.0.1, 9.5.0.1, and 9.0.0.1) is affected by a critical SQL injection vulnerability. An unauthenticated attacker can exploit this flaw to execute arbitrary SQL statements against the underlying database. The vulnerability can be further leveraged to write a web shell to the application web root, enabling full remote code execution. No authentication is required to exploit this vulnerability, significantly increasing its risk. The impact is critical as it allows complete server compromise. IBM has published an advisory with remediation guidance. Organizations using affected versions should prioritize patching immediately.