CVE-2026-84239
7.6IBM · Guardium Data Protection
IBM Guardium Data Protection 12.2 is vulnerable to SQL injection, allowing a remote authenticated attacker to retrieve sensitive information.
Executive summary
A high-severity SQL injection vulnerability in IBM Guardium Data Protection 12.2 allows an authenticated attacker to perform unauthorized data extraction.
Vulnerability
The application is susceptible to CWE-89, where improper neutralization of special elements in SQL commands enables an authenticated attacker to execute unauthorized queries. The vulnerability requires high privileges (PR:H) to reach the affected endpoint, as indicated by the CVSS vector.
Business impact
The ability to perform SQL injection against a data protection platform poses a significant risk to organizational confidentiality. A successful exploit could lead to the unauthorized disclosure of protected database contents, resulting in severe compliance violations and potential loss of intellectual property. With a CVSS score of 7.6, the vulnerability is classified as High, reflecting the potential for significant impact on data integrity and security controls.
Remediation
Immediate Action: Apply the vendor-provided fix by upgrading to the version specified in the IBM Fix Central portal, identified as SqlGuard_12.0p233_FixPack.
Proactive Monitoring: Review database access logs for anomalous query patterns, specifically looking for unexpected syntax or unauthorized attempts to access system-level tables.
Compensating Controls: Deploy or update Web Application Firewall rules to detect and block common SQL injection payloads targeted at the management interface of the Guardium appliance.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the critical role of Guardium Data Protection in securing enterprise data, this vulnerability must be treated with high priority. Administrators should verify their current deployment version and apply the mandatory patch provided by IBM immediately to prevent potential data exfiltration by malicious actors.
More IBM CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief high section