Impact
IBM Guardium Data Protection 12.2 is vulnerable to an SQL injection flaw caused by improper neutralization of special elements used in an SQL command, which is a classic CWE‑89 weakness. An attacker who can supply inputs to a vulnerable component could cause the system to execute arbitrary SQL statements, potentially yielding unauthorized data access, data modification, or full system compromise. The vulnerability enables a remote attacker to leverage the database layer to exfiltrate or corrupt sensitive information, thereby harming confidentiality, integrity, and availability of protected data.
Affected Systems
The affected component is IBM Guardium Data Protection version 12.2.0 and any minor releases of 12.2 that have not applied the designated fix pack from IBM’s Fix Central. The recommended remedy is to install the fix pack "SqlGuard_12.0p233_FixPack" available through IBM’s support portal, which addresses the SQL injection vulnerability.
Risk and Exploitability
The CVSS base score of 9.8 marks this as a critical impact with very high exploitation potential when the flaw is present. EPSS data is not available, so the precise likelihood of exploitation cannot be quantified, but the lack of KEV listing does not mitigate the immediate risk. The vulnerability can be triggered remotely by supplying malicious input to an affected interface, so attackers with network access to the Guardium system could readily exploit it unless patched or otherwise mitigated.
OpenCVE Enrichment