Impact
IBM Guardium Data Protection 12.2 is vulnerable to an SQL injection flaw that allows a remote authenticated attacker to run arbitrary SQL commands. The weakness stems from improper neutralization of special elements within an SQL statement, enabling the attacker to execute injected code and potentially gain full control of the protected database. This vulnerability is classified as CWE-89 and can lead to complete compromise of confidentiality and integrity for the database managed by Guardium.
Affected Systems
The issue affects IBM Guardium Data Protection version 12.2 deployed on Linux platforms. Only installations of this specific product and version are impacted.
Risk and Exploitability
The CVSS score of 9.1 indicates a high severity scenario. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack vector requires remote authenticated access, meaning privileged users or compromised credentials could exploit this flaw to execute arbitrary SQL commands, potentially escalating privileges or exfiltrating sensitive data.
OpenCVE Enrichment