Impact
IBM Guardium Data Protection 12.2 contains an unauthenticated second‑order SQL injection flaw within the generateInsertQuery function used by the change‑tracker data engine. By crafting a malicious payload that is later incorporated into an internal SQL statement, a remote adversary could execute arbitrary SQL on the database host, leading to compromise of confidentiality, integrity, and availability of the protected data. The weakness aligns with CWE‑89, indicating classic SQL injection problems.
Affected Systems
The vulnerability affects IBM Guardium Data Protection version 12.2. Users running the 12.2 release, especially on Linux platforms, are impacted. IBM has released a fix for this version and recommends applying the update promptly.
Risk and Exploitability
The CVSS score of 9.8 signifies critical severity. While EPSS data is not publicly available, the absence of a KEV listing does not diminish the risk; the vulnerability allows unauthenticated remote exploitation. Attackers only need to reach the affected endpoint and send a crafted request to trigger the injection. Once exploited, they can gain full control over the database server and potentially all data monitored by Guardium.
OpenCVE Enrichment