Executive brief
IBM Guardium Data Protection, a database security and monitoring appliance, contains a SQL injection flaw in its analytics reporting component. A low-privileged authenticated user can inject malicious SQL commands to access, modify, or delete sensitive data and potentially disrupt the system's operation.
Technical details
SQL injection in the Analytic Grid Service Handler endpoint allows authenticated users to inject arbitrary SQL commands. Attack vector is network-based with low privilege requirements and no user interaction needed. An attacker gains read, write, and delete access to backend database contents, compromising confidentiality, integrity, and availability of Guardium and monitored systems.
Affected products
- IBM Guardium Data Protection 12.2
Timeline
- 2026-09-18: disclosed