Description
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to obtain sensitive information due to improper neutralization of special elements used in an SQL command.
Published: 2026-09-18
Score: 7.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Authenticated SQL Injection leading to confidential data exposure
Action: Apply Patch
AI Analysis

Impact

IBM Guardium Data Protection 12.2 contains a vulnerability that allows a remote authenticated attacker to supply unsanitized input to an SQL command, enabling SQL injection. The inadequate neutralization of special characters permits the attacker to execute arbitrary queries and retrieve sensitive information, compromising confidentiality of stored data. The flaw is classified as CWE‑89, indicating an injection weakness that can be exploited when input is incorporated into SQL statements without proper escaping.

Affected Systems

The affected product is IBM Guardium Data Protection version 12.2 on Linux platforms. Customers operating this version are at risk; no other versions or product families are listed as affected, and the advisory explicitly mentions a fix for 12.2.

Risk and Exploitability

The CVSS score of 7.6 indicates high severity, and although the EPSS score is not available, the lack of a KEV listing suggests no confirmed field‑of‑play exploits yet. The vulnerability requires an authenticated session, implying attackers must compromise credentials or gain legitimate access. Once they are authenticated, they can exploit the injection flaw to exfiltrate data, representing an elevated risk to confidentiality for affected installations.

Generated by OpenCVE AI on September 19, 2026 at 13:53 UTC.

Remediation

Vendor Solution

IBM encourages customers to update their systems promptly.  ProductVersions FixIBM Guardium Data Protection12.2 https://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Security&product=ibm/Information+Management/InfoSphere+Guardium&release=12.2&platform=Linux&function=fixId&fixids=SqlGuard_12.0p233_FixPack&includeSupersedes=0&source=fc


OpenCVE Recommended Actions

  • Update IBM Guardium Data Protection 12.2 by applying the IBM fix pack 12.0p233 or later as provided by the vendor. This patch neutralizes the SQL injection vector and reconfigures any interfaces or plugins that construct SQL commands from user input to enforce strict parameterization or use whitelisting, thereby preventing malicious payloads from being executed.
  • Audit database logs for anomalous query patterns and enforce least‑privilege access for database accounts, ensuring that compromised credentials cannot be used to extract large volumes of data.
  • Limit privileged user privileges and perform a comprehensive security review of all input handling code paths to ensure proper parameterization and input validation throughout the application.

Generated by OpenCVE AI on September 19, 2026 at 13:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to obtain sensitive information due to improper neutralization of special elements used in an SQL command.
Title IBM Guardium Data Protection is affected by multiple vulnerabilities.
First Time appeared Ibm
Ibm guardium Data Protection
Weaknesses CWE-89
CPEs cpe:2.3:a:ibm:guardium_data_protection:12.2.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:guardium_data_protection:12.2:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm guardium Data Protection
References
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L'}


Subscriptions

Ibm Guardium Data Protection
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-19T14:01:28.354Z

Reserved: 2026-09-01T13:04:07.305Z

Link: CVE-2026-84239

cve-icon Vulnrichment

Updated: 2026-09-19T13:59:43.504Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-18T20:17:28.887

Modified: 2026-10-06T15:32:31.050

Link: CVE-2026-84239

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T03:45:12Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')