CVE-2026-84064
9.9IBM · Guardium Data Protection
IBM Guardium Data Protection 12.2 contains an SQL injection vulnerability that allows an authenticated attacker to execute arbitrary SQL commands.
Executive summary
A critical SQL injection vulnerability in IBM Guardium Data Protection 12.2 enables remote authenticated attackers to execute arbitrary database commands, posing a severe risk of data compromise.
Vulnerability
The application is susceptible to SQL injection (CWE-89) due to improper neutralization of special elements within SQL commands. This flaw permits an authenticated user to manipulate database queries, leading to unauthorized data access or modification.
Business impact
The vulnerability carries a CVSS score of 9.9, reflecting its potential for full system compromise. Successful exploitation allows an attacker to bypass data security controls, which could lead to the exposure of sensitive organizational information, loss of data integrity, and total system compromise within the Guardium environment.
Remediation
Immediate Action: Update IBM Guardium Data Protection to the version provided in the IBM Fix Central portal, specifically applying the fix pack SqlGuard 12.0p233.
Proactive Monitoring: Review database access logs for unusual queries, unexpected syntax patterns, or unauthorized attempts to access system tables.
Compensating Controls: Implement strict database user permission controls to limit the blast radius of any compromised account, and utilize a Web Application Firewall to inspect traffic for common SQL injection payloads.
Exploitation status
Public Exploit Available: No (exploit_available: false).
Analyst recommendation
Given the critical severity and the nature of Guardium as a security-focused product, the risk of unauthorized data access is extreme. Administrators must prioritize the application of the specified fix pack immediately to secure the database environment against potential exploitation.
More IBM CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief critical section