Description
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to obtain sensitive information due to improper neutralization of special elements used in an SQL command.
Published: 2026-09-18
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote disclosure of sensitive information via SQL injection
Action: Patch
AI Analysis

Impact

IBM Guardium Data Protection 12.2 contains an SQL injection flaw that allows a remote authenticated attacker to execute malicious SQL commands and read sensitive data. The vulnerability arises from improper neutralization of special elements in SQL statements, enabling confidentiality compromise. The weakness is classified as CWE‑89.

Affected Systems

The affected product is IBM Guardium Data Protection, version any release within the 12.2 series. The official fix is available for this version.

Risk and Exploitability

The CVSS score of 7.7 indicates a high risk level. The EPSS is unavailable and the vulnerability is not listed in the CISA KEV catalog. Attackers would need valid credentials to the Guardium system and could exploit the flaw remotely by sending crafted SQL text through an exposed interface. The impact is limited to information disclosure and requires the attacker to have authenticated access.

Generated by OpenCVE AI on September 19, 2026 at 13:54 UTC.

Remediation

Vendor Solution

IBM encourages customers to update their systems promptly.  ProductVersions FixIBM Guardium Data Protection12.2 https://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Security&product=ibm/Information+Management/InfoSphere+Guardium&release=12.2&platform=Linux&function=fixId&fixids=SqlGuard_12.0p233_FixPack&includeSupersedes=0&source=fc


OpenCVE Recommended Actions

  • Deploy the IBM Guardium Data Protection 12.2 Fix Pack 12.0p233 as provided by IBM.
  • Enforce strict access controls so that only authorized users with the minimum necessary privileges can interact with the Guardium database interface.
  • Validate or parameterize all inputs to the Guardium system to ensure that unfiltered SQL commands cannot be executed.

Generated by OpenCVE AI on September 19, 2026 at 13:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to obtain sensitive information due to improper neutralization of special elements used in an SQL command.
Title IBM Guardium Data Protection is affected by multiple vulnerabilities.
First Time appeared Ibm
Ibm guardium Data Protection
Weaknesses CWE-89
CPEs cpe:2.3:a:ibm:guardium_data_protection:12.2.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:guardium_data_protection:12.2:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm guardium Data Protection
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

Ibm Guardium Data Protection
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-19T14:01:28.802Z

Reserved: 2026-09-01T07:02:47.887Z

Link: CVE-2026-84105

cve-icon Vulnrichment

Updated: 2026-09-19T14:00:20.361Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-18T20:17:28.510

Modified: 2026-10-06T15:32:55.050

Link: CVE-2026-84105

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:36:00Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')