CVE-2026-81933

8.8

IBM · Guardium Data Protection

IBM Guardium Data Protection 12.2 contains a SQL injection vulnerability in the Analytic Grid Service Handler, allowing authenticated users to execute arbitrary SQL commands.

Executive summary

A critical SQL injection vulnerability in IBM Guardium Data Protection 12.2 allows low-privileged authenticated users to compromise the confidentiality, integrity, and availability of sensitive database information.

Vulnerability

The application is susceptible to SQL injection (CWE-89) within the Analytic Grid Service Handler. An attacker with low-privileged authenticated access can inject malicious SQL statements via the analytic cases grid endpoint to manipulate database queries.

Business impact

Successful exploitation of this vulnerability grants an attacker the ability to bypass security controls and interact directly with the backend database. This could lead to unauthorized data exfiltration, modification of sensitive records, or complete service disruption, posing a significant risk to organizational data privacy and compliance. With a CVSS score of 8.8, this flaw represents a high-severity threat that requires immediate attention to prevent unauthorized access to critical data infrastructure.

Remediation

Immediate Action: Update IBM Guardium Data Protection to the version provided in the vendor patch, specifically applying the SqlGuard_12.0p233_FixPack available via IBM Fix Central.

Proactive Monitoring: Audit database access logs for unusual query patterns, specifically monitoring the analytic cases grid endpoint for anomalous SQL syntax or unauthorized access attempts.

Compensating Controls: Implement a Web Application Firewall (WAF) with updated rulesets designed to detect and block common SQL injection patterns targeting application endpoints.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

The presence of a SQL injection vulnerability in a data protection product is particularly concerning given the sensitivity of the data managed by the platform. Administrators should prioritize the deployment of the provided fix pack to eliminate the injection vector. Ensure that internal access controls are strictly enforced to minimize the number of users with the low-privilege access required to trigger this vulnerability.

More IBM CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources