Description
IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary SQL commands due to improper neutralization of special elements used in an SQL command.
Published: 2026-09-18
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

IBM Guardium Data Protection 12.2 is vulnerable to an SQL injection flaw caused by improper neutralization of special elements used in an SQL command, which is a classic CWE‑89 weakness. An attacker who can supply inputs to a vulnerable component could cause the system to execute arbitrary SQL statements, potentially yielding unauthorized data access, data modification, or full system compromise. The vulnerability enables a remote attacker to leverage the database layer to exfiltrate or corrupt sensitive information, thereby harming confidentiality, integrity, and availability of protected data.

Affected Systems

The affected component is IBM Guardium Data Protection version 12.2.0 and any minor releases of 12.2 that have not applied the designated fix pack from IBM’s Fix Central. The recommended remedy is to install the fix pack "SqlGuard_12.0p233_FixPack" available through IBM’s support portal, which addresses the SQL injection vulnerability.

Risk and Exploitability

The CVSS base score of 9.8 marks this as a critical impact with very high exploitation potential when the flaw is present. EPSS data is not available, so the precise likelihood of exploitation cannot be quantified, but the lack of KEV listing does not mitigate the immediate risk. The vulnerability can be triggered remotely by supplying malicious input to an affected interface, so attackers with network access to the Guardium system could readily exploit it unless patched or otherwise mitigated.

Generated by OpenCVE AI on September 19, 2026 at 13:56 UTC.

Remediation

Vendor Solution

IBM encourages customers to update their systems promptly.  ProductVersions FixIBM Guardium Data Protection12.2 https://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Security&product=ibm/Information+Management/InfoSphere+Guardium&release=12.2&platform=Linux&function=fixId&fixids=SqlGuard_12.0p233_FixPack&includeSupersedes=0&source=fc


OpenCVE Recommended Actions

  • Apply the IBM Fix Central update "SqlGuard_12.0p233_FixPack" for Guardium Data Protection 12.2 to eliminate the injection flaw.
  • Restart Guardium Data Protection services to load the updated code.
  • Implement input validation or parameterized queries for any custom SQL interfaces to ensure that user-supplied input is properly sanitized, reducing the risk of injection until the issue is fully confirmed fixed.

Generated by OpenCVE AI on September 19, 2026 at 13:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary SQL commands due to improper neutralization of special elements used in an SQL command.
Title IBM Guardium Data Protection is affected by multiple vulnerabilities.
First Time appeared Ibm
Ibm guardium Data Protection
Weaknesses CWE-89
CPEs cpe:2.3:a:ibm:guardium_data_protection:12.2.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:guardium_data_protection:12.2:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm guardium Data Protection
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Ibm Guardium Data Protection
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-23T03:55:55.603Z

Reserved: 2026-09-01T06:21:48.429Z

Link: CVE-2026-84082

cve-icon Vulnrichment

Updated: 2026-09-19T14:01:34.220Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-18T20:17:27.743

Modified: 2026-10-06T15:33:52.273

Link: CVE-2026-84082

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T00:30:16Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')