Description
IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability in the Analytic Grid Service Handler. A low-privileged authenticated user can inject SQL statements through the analytic cases grid endpoint, potentially resulting in unauthorized access to sensitive data and impact to the confidentiality, integrity, and availability of the affected system.
Published: 2026-09-18
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized SQL injection enabling data exposure and potential integrity and availability impact
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is a classic SQL injection flaw in the Analytic Grid Service Handler of IBM Guardium Data Protection 12.2. A low‑privileged authenticated user can supply crafted input to the analytic cases grid endpoint, allowing direct injection of arbitrary SQL statements. This can lead to unauthorized reading or modification of protected data, as well as potential disruption of the analytic service.

Affected Systems

IBM Guardium Data Protection version 12.2 is affected. The fix is bundled in the IBM Guardium Data Protection 12.2 fix pack, which should be applied to all installations of this version.

Risk and Exploitability

The high CVSS score of 8.8 reflects the severity of the flaw. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, but the attack requires only a low‑privileged authenticated session and access to the analytic grid endpoint, which are typically reachable over the network. An attacker who succeeds could compromise confidentiality, integrity, and availability of the Guardium environment.

Generated by OpenCVE AI on September 19, 2026 at 11:35 UTC.

Remediation

Vendor Solution

IBM encourages customers to update their systems promptly.  ProductVersions FixIBM Guardium Data Protection12.2 https://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Security&product=ibm/Information+Management/InfoSphere+Guardium&release=12.2&platform=Linux&function=fixId&fixids=SqlGuard_12.0p233_FixPack&includeSupersedes=0&source=fc


OpenCVE Recommended Actions

  • Upgrade IBM Guardium Data Protection to 12.2 using the provided fix pack or a later release that includes the patch.
  • Restrict network access to the Analytic Grid Service Handler so that only trusted hosts and authenticated users can reach the endpoint.
  • Apply the principle of least privilege: remove or limit the permissions of low‑privileged accounts that can access the analytic cases grid endpoint.
  • Monitor Guardium logs for anomalous SQL queries or repeated injection attempts and investigate promptly.

Generated by OpenCVE AI on September 19, 2026 at 11:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability in the Analytic Grid Service Handler. A low-privileged authenticated user can inject SQL statements through the analytic cases grid endpoint, potentially resulting in unauthorized access to sensitive data and impact to the confidentiality, integrity, and availability of the affected system.
Title IBM Guardium Data Protection is affected by multiple vulnerabilities.
First Time appeared Ibm
Ibm guardium Data Protection
Weaknesses CWE-89
CPEs cpe:2.3:a:ibm:guardium_data_protection:12.2.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:guardium_data_protection:12.2:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm guardium Data Protection
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Ibm Guardium Data Protection
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-18T19:28:48.729Z

Reserved: 2026-08-27T19:03:10.745Z

Link: CVE-2026-81933

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-18T20:17:24.250

Modified: 2026-09-18T20:17:24.250

Link: CVE-2026-81933

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T11:45:08Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')