Impact
A SQL injection flaw exists in IBM Guardium Data Protection 12.2’s New Query Builder REST Processor. An authenticated user with low privileges can send crafted requests to the newQueryBuilder endpoint, embedding arbitrary SQL statements that are executed against the backend database. This vulnerability, classified as CWE‑89, allows attackers to bypass normal authorization and gain read, modify or delete access to protected data, thereby compromising confidentiality, integrity and availability of the system.
Affected Systems
The software affected is IBM Guardium Data Protection, specifically versions 12.2.0 and 12.2.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity risk. Although there is no EPSS score available, the lack of a KEV listing does not diminish the potential impact; the issue is exploitable through any network path that exposes the newQueryBuilder REST endpoint to authenticated users. Attackers need only legitimate credentials with low privileges, a situation that can arise from legitimate user accounts. The high impact combined with the required but common access conditions makes this a significant threat that warrants immediate attention.
OpenCVE Enrichment