CVE-2026-84105

7.7

IBM · Guardium Data Protection

IBM Guardium Data Protection 12.2 is vulnerable to SQL injection, potentially allowing an authenticated remote attacker to access sensitive information.

Executive summary

A vulnerability in IBM Guardium Data Protection 12.2 allows an authenticated attacker to perform SQL injection and gain unauthorized access to sensitive data.

Vulnerability

This is an SQL injection vulnerability (CWE-89) arising from improper neutralization of special elements in SQL commands. The vulnerability requires the attacker to have an authenticated user session to trigger the flaw through the affected interface.

Business impact

The ability to perform unauthorized SQL queries poses a severe risk to data confidentiality, as it allows attackers to extract sensitive information from the underlying database. With a CVSS score of 7.7, this flaw is classified as high severity, reflecting the significant potential for data exfiltration and the compromise of protected database assets within the enterprise environment.

Remediation

Immediate Action: Update IBM Guardium Data Protection to the version provided in the vendor security fix (SqlGuard_12.0p233_FixPack) available via IBM Fix Central.

Proactive Monitoring: Review database audit logs for unusual query patterns or syntax errors that may indicate injection attempts by authenticated users.

Compensating Controls: Deploy or update Web Application Firewall (WAF) rules to inspect and block malicious SQL syntax originating from authenticated sessions.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the high CVSS score and the direct threat to database security, administrators must prioritize the application of the provided fix pack. Ensure that all user access is strictly controlled and audited, as this vulnerability specifically targets the trust placed in authenticated sessions to interact with database interfaces.

More IBM CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources