Impact
IBM Guardium Data Protection 12.2 contains an SQL injection flaw that allows a remote authenticated attacker to execute malicious SQL commands and read sensitive data. The vulnerability arises from improper neutralization of special elements in SQL statements, enabling confidentiality compromise. The weakness is classified as CWE‑89.
Affected Systems
The affected product is IBM Guardium Data Protection, version any release within the 12.2 series. The official fix is available for this version.
Risk and Exploitability
The CVSS score of 7.7 indicates a high risk level. The EPSS is unavailable and the vulnerability is not listed in the CISA KEV catalog. Attackers would need valid credentials to the Guardium system and could exploit the flaw remotely by sending crafted SQL text through an exposed interface. The impact is limited to information disclosure and requires the attacker to have authenticated access.
OpenCVE Enrichment