Description
IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability in the New Query Builder REST Processor. A low-privileged authenticated user can inject SQL statements through the newQueryBuilder REST endpoint, potentially resulting in unauthorized access to data and impact to the confidentiality, integrity, and availability of the affected system.
Published: 2026-09-18
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Data Access
Action: Patch
AI Analysis

Impact

A SQL injection flaw exists in IBM Guardium Data Protection 12.2’s New Query Builder REST Processor. An authenticated user with low privileges can send crafted requests to the newQueryBuilder endpoint, embedding arbitrary SQL statements that are executed against the backend database. This vulnerability, classified as CWE‑89, allows attackers to bypass normal authorization and gain read, modify or delete access to protected data, thereby compromising confidentiality, integrity and availability of the system.

Affected Systems

The software affected is IBM Guardium Data Protection, specifically versions 12.2.0 and 12.2.

Risk and Exploitability

The CVSS score of 8.8 indicates a high severity risk. Although there is no EPSS score available, the lack of a KEV listing does not diminish the potential impact; the issue is exploitable through any network path that exposes the newQueryBuilder REST endpoint to authenticated users. Attackers need only legitimate credentials with low privileges, a situation that can arise from legitimate user accounts. The high impact combined with the required but common access conditions makes this a significant threat that warrants immediate attention.

Generated by OpenCVE AI on September 19, 2026 at 11:56 UTC.

Remediation

Vendor Solution

IBM encourages customers to update their systems promptly.  ProductVersions FixIBM Guardium Data Protection12.2 https://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Security&product=ibm/Information+Management/InfoSphere+Guardium&release=12.2&platform=Linux&function=fixId&fixids=SqlGuard_12.0p233_FixPack&includeSupersedes=0&source=fc


OpenCVE Recommended Actions

  • Upgrade IBM Guardium Data Protection to version 12.2 or later using the fix pack provided by IBM
  • Limit the privileges of user accounts that have access to the newQueryBuilder REST endpoint; consider revoking access from low‑privileged roles
  • Configure the Guardium REST API to be accessible only over HTTPS, restrict network access to trusted IP ranges, and enable detailed logging of SQL query activity so anomalous injections can be detected and investigated

Generated by OpenCVE AI on September 19, 2026 at 11:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability in the New Query Builder REST Processor. A low-privileged authenticated user can inject SQL statements through the newQueryBuilder REST endpoint, potentially resulting in unauthorized access to data and impact to the confidentiality, integrity, and availability of the affected system.
Title IBM Guardium Data Protection is affected by multiple vulnerabilities.
First Time appeared Ibm
Ibm guardium Data Protection
Weaknesses CWE-89
CPEs cpe:2.3:a:ibm:guardium_data_protection:12.2.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:guardium_data_protection:12.2:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm guardium Data Protection
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Ibm Guardium Data Protection
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-19T14:11:39.726Z

Reserved: 2026-08-27T09:45:27.661Z

Link: CVE-2026-81656

cve-icon Vulnrichment

Updated: 2026-09-19T14:06:46.793Z

cve-icon NVD

Status : Received

Published: 2026-09-18T20:17:23.867

Modified: 2026-09-19T15:17:03.380

Link: CVE-2026-81656

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T12:00:08Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')