Impact
IBM Guardium Data Protection 12.2 has a SQL injection flaw in the Load Balancer Groups component. An unauthenticated attacker can send crafted requests to the Load Balancer Servlet endpoint and embed malicious SQL code. This vulnerability enables unauthorized access to confidential data, tampering with stored information, and can disrupt the availability of the protected system.
Affected Systems
The vulnerability affects IBM Guardium Data Protection version 12.2, running on Linux platforms.
Risk and Exploitability
The CVSS score of 8.6 classifies this issue as high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, indicating no currently documented exploits. Based on the description, the likely attack vector is remote; the servlet endpoint must be reachable over the network, and authentication is not required. If an attacker can reach the endpoint, they can inject SQL commands and compromise data confidentiality, integrity, and availability.
OpenCVE Enrichment