Impact
The vulnerability is a classic SQL injection flaw in the Analytic Grid Service Handler of IBM Guardium Data Protection 12.2. A low‑privileged authenticated user can supply crafted input to the analytic cases grid endpoint, allowing direct injection of arbitrary SQL statements. This can lead to unauthorized reading or modification of protected data, as well as potential disruption of the analytic service.
Affected Systems
IBM Guardium Data Protection version 12.2 is affected. The fix is bundled in the IBM Guardium Data Protection 12.2 fix pack, which should be applied to all installations of this version.
Risk and Exploitability
The high CVSS score of 8.8 reflects the severity of the flaw. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, but the attack requires only a low‑privileged authenticated session and access to the analytic grid endpoint, which are typically reachable over the network. An attacker who succeeds could compromise confidentiality, integrity, and availability of the Guardium environment.
OpenCVE Enrichment