Impact
IBM Guardium Data Protection 12.2 contains an SQL injection flaw caused by improper neutralization of special elements in an SQL command. This weakness allows a remote authenticated attacker to inject arbitrary SQL statements, potentially enabling unauthorized data read or write operations, data exfiltration, or further compromise of the underlying database system.
Affected Systems
The issue affects IBM Guardium Data Protection version 12.2, specifically the 12.2.0 build running on Linux. Customers should apply the IBM Fix Pack SqlGuard_12.0p233_FixPack available on the IBM Support site linked in the advisory.
Risk and Exploitability
The CVSS score of 9.9 denotes critical severity, and the EPSS score of less than 1% indicates a low likelihood of being exploited in the wild. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attacker must be authenticated and can launch the attack from a remote location, making the exploit possible over the network. The combination of remote access, authentication requirements, and high impact results in a significant risk for unpatched systems.
OpenCVE Enrichment