Impact
IBM Guardium Data Protection 12.2 contains a vulnerability that allows a remote authenticated attacker to supply unsanitized input to an SQL command, enabling SQL injection. The inadequate neutralization of special characters permits the attacker to execute arbitrary queries and retrieve sensitive information, compromising confidentiality of stored data. The flaw is classified as CWE‑89, indicating an injection weakness that can be exploited when input is incorporated into SQL statements without proper escaping.
Affected Systems
The affected product is IBM Guardium Data Protection version 12.2 on Linux platforms. Customers operating this version are at risk; no other versions or product families are listed as affected, and the advisory explicitly mentions a fix for 12.2.
Risk and Exploitability
The CVSS score of 7.6 indicates high severity, and although the EPSS score is not available, the lack of a KEV listing suggests no confirmed field‑of‑play exploits yet. The vulnerability requires an authenticated session, implying attackers must compromise credentials or gain legitimate access. Once they are authenticated, they can exploit the injection flaw to exfiltrate data, representing an elevated risk to confidentiality for affected installations.
OpenCVE Enrichment