Description
IBM Guardium Data Protection 12.2 is vulnerable to an unauthenticated second-order SQL injection vulnerability in the generateInsertQuery functionality of change-tracker-data.sql. A remote attacker could inject malicious SQL that is subsequently processed by the application, potentially resulting in compromise of the confidentiality, integrity, and availability of the affected system.
Published: 2026-09-18
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Prompt Patch
AI Analysis

Impact

IBM Guardium Data Protection 12.2 contains an unauthenticated second‑order SQL injection flaw within the generateInsertQuery function used by the change‑tracker data engine. By crafting a malicious payload that is later incorporated into an internal SQL statement, a remote adversary could execute arbitrary SQL on the database host, leading to compromise of confidentiality, integrity, and availability of the protected data. The weakness aligns with CWE‑89, indicating classic SQL injection problems.

Affected Systems

The vulnerability affects IBM Guardium Data Protection version 12.2. Users running the 12.2 release, especially on Linux platforms, are impacted. IBM has released a fix for this version and recommends applying the update promptly.

Risk and Exploitability

The CVSS score of 9.8 signifies critical severity. While EPSS data is not publicly available, the absence of a KEV listing does not diminish the risk; the vulnerability allows unauthenticated remote exploitation. Attackers only need to reach the affected endpoint and send a crafted request to trigger the injection. Once exploited, they can gain full control over the database server and potentially all data monitored by Guardium.

Generated by OpenCVE AI on September 19, 2026 at 11:57 UTC.

Remediation

Vendor Solution

IBM encourages customers to update their systems promptly.  ProductVersions FixIBM Guardium Data Protection12.2 https://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Security&product=ibm/Information+Management/InfoSphere+Guardium&release=12.2&platform=Linux&function=fixId&fixids=SqlGuard_12.0p233_FixPack&includeSupersedes=0&source=fc


OpenCVE Recommended Actions

  • Apply the IBM Guardium 12.2 fix pack referenced in the IBM Fix Central link. This patch resolves the second‑order SQL injection by sanitizing input prior to query assembly.
  • Restrict network access to the Guardium database back‑end to trusted hosts by configuring firewall rules to limit exposure of the database server.
  • Limit the permissions of the Guardium database user to only SELECT and necessary read operations, revoking any privileges to modify or drop database objects.

Generated by OpenCVE AI on September 19, 2026 at 11:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description IBM Guardium Data Protection 12.2 is vulnerable to an unauthenticated second-order SQL injection vulnerability in the generateInsertQuery functionality of change-tracker-data.sql. A remote attacker could inject malicious SQL that is subsequently processed by the application, potentially resulting in compromise of the confidentiality, integrity, and availability of the affected system.
Title IBM Guardium Data Protection is affected by multiple vulnerabilities.
First Time appeared Ibm
Ibm guardium Data Protection
Weaknesses CWE-89
CPEs cpe:2.3:a:ibm:guardium_data_protection:12.2.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:guardium_data_protection:12.2:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm guardium Data Protection
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Ibm Guardium Data Protection
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-23T03:55:39.303Z

Reserved: 2026-08-26T11:11:06.566Z

Link: CVE-2026-80441

cve-icon Vulnrichment

Updated: 2026-09-19T14:07:23.158Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-18T20:17:23.217

Modified: 2026-10-06T14:32:54.477

Link: CVE-2026-80441

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T01:00:11Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')