Description
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary SQL commands due to improper neutralization of special elements used in an SQL command.
Published: 2026-09-18
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution via SQL Injection
Action: Apply Patch
AI Analysis

Impact

IBM Guardium Data Protection 12.2 is vulnerable to an SQL injection flaw that allows a remote authenticated attacker to run arbitrary SQL commands. The weakness stems from improper neutralization of special elements within an SQL statement, enabling the attacker to execute injected code and potentially gain full control of the protected database. This vulnerability is classified as CWE-89 and can lead to complete compromise of confidentiality and integrity for the database managed by Guardium.

Affected Systems

The issue affects IBM Guardium Data Protection version 12.2 deployed on Linux platforms. Only installations of this specific product and version are impacted.

Risk and Exploitability

The CVSS score of 9.1 indicates a high severity scenario. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack vector requires remote authenticated access, meaning privileged users or compromised credentials could exploit this flaw to execute arbitrary SQL commands, potentially escalating privileges or exfiltrating sensitive data.

Generated by OpenCVE AI on September 19, 2026 at 13:34 UTC.

Remediation

Vendor Solution

IBM encourages customers to update their systems promptly.  ProductVersions FixIBM Guardium Data Protection12.2 https://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Security&product=ibm/Information+Management/InfoSphere+Guardium&release=12.2&platform=Linux&function=fixId&fixids=SqlGuard_12.0p233_FixPack&includeSupersedes=0&source=fc


OpenCVE Recommended Actions

  • Apply the IBM Guardium Data Protection 12.2 FixPack SqlGuard_12.0p233_FixPack to update the affected system
  • Limit network connectivity to the Guardium instance to trusted administrative networks and enforce strict access controls on credentials
  • Ensure that Guardium database accounts operate with the minimum privileges required, and monitor audit logs for abnormal SQL activity

Generated by OpenCVE AI on September 19, 2026 at 13:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary SQL commands due to improper neutralization of special elements used in an SQL command.
Title IBM Guardium Data Protection is affected by multiple vulnerabilities.
First Time appeared Ibm
Ibm guardium Data Protection
Weaknesses CWE-89
CPEs cpe:2.3:a:ibm:guardium_data_protection:12.2.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:guardium_data_protection:12.2:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm guardium Data Protection
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L'}


Subscriptions

Ibm Guardium Data Protection
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-19T14:11:37.287Z

Reserved: 2026-09-01T06:13:27.908Z

Link: CVE-2026-84073

cve-icon Vulnrichment

Updated: 2026-09-19T14:03:24.448Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-18T20:17:26.830

Modified: 2026-10-06T16:26:56.807

Link: CVE-2026-84073

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T00:30:16Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')