CVE-2026-84064

9.9

IBM · Guardium Data Protection

IBM Guardium Data Protection 12.2 contains an SQL injection vulnerability that allows an authenticated attacker to execute arbitrary SQL commands.

Executive summary

A critical SQL injection vulnerability in IBM Guardium Data Protection 12.2 enables remote authenticated attackers to execute arbitrary database commands, posing a severe risk of data compromise.

Vulnerability

The application is susceptible to SQL injection (CWE-89) due to improper neutralization of special elements within SQL commands. This flaw permits an authenticated user to manipulate database queries, leading to unauthorized data access or modification.

Business impact

The vulnerability carries a CVSS score of 9.9, reflecting its potential for full system compromise. Successful exploitation allows an attacker to bypass data security controls, which could lead to the exposure of sensitive organizational information, loss of data integrity, and total system compromise within the Guardium environment.

Remediation

Immediate Action: Update IBM Guardium Data Protection to the version provided in the IBM Fix Central portal, specifically applying the fix pack SqlGuard 12.0p233.

Proactive Monitoring: Review database access logs for unusual queries, unexpected syntax patterns, or unauthorized attempts to access system tables.

Compensating Controls: Implement strict database user permission controls to limit the blast radius of any compromised account, and utilize a Web Application Firewall to inspect traffic for common SQL injection payloads.

Exploitation status

Public Exploit Available: No (exploit_available: false).

Analyst recommendation

Given the critical severity and the nature of Guardium as a security-focused product, the risk of unauthorized data access is extreme. Administrators must prioritize the application of the specified fix pack immediately to secure the database environment against potential exploitation.

More IBM CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief critical section

Sources