CVE-2026-81656

8.8

IBM · Guardium Data Protection

IBM Guardium Data Protection version 12.2 is susceptible to a SQL injection vulnerability within the New Query Builder REST processor, allowing low-privileged users to execute arbitrary SQL commands.

Executive summary

A high-severity SQL injection vulnerability in IBM Guardium Data Protection 12.2 allows authenticated users to compromise data confidentiality, integrity, and availability.

Vulnerability

This is a SQL injection vulnerability (CWE-89) located in the newQueryBuilder REST endpoint. The flaw allows any low-privileged authenticated user to inject malicious SQL statements, which the system processes without proper neutralization.

Business impact

Successful exploitation of this vulnerability could lead to unauthorized access to sensitive database information, modification of data, or complete disruption of security auditing services provided by the Guardium platform. Given the CVSS score of 8.8, this flaw presents a significant risk to the organization's data protection posture, potentially resulting in severe regulatory non-compliance and loss of trust.

Remediation

Immediate Action: Update to the patched version by applying the SqlGuard_12.0p233_FixPack via the IBM Fix Central portal.

Proactive Monitoring: Review database access logs and audit trails for anomalous query patterns or unexpected REST API activity originating from low-privileged accounts.

Compensating Controls: Implement strict Web Application Firewall (WAF) rules to inspect and filter incoming traffic to the /newQueryBuilder REST endpoint for SQL syntax patterns.

Exploitation status

Public Exploit Available: No

Analyst recommendation

The vulnerability represents a critical risk to the integrity of the data protection environment. Organizations using IBM Guardium Data Protection 12.2 should prioritize the deployment of the provided fix pack immediately to eliminate the injection vector and secure the administrative interface against unauthorized database interaction.

More IBM CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources