Executive brief
IBM Guardium Data Protection is a database security and monitoring appliance used to protect sensitive data and audit database activity. A remote authenticated attacker can inject arbitrary SQL commands through the application, allowing them to view, modify, or delete database records and potentially compromise confidential information stored in the protected databases.
Technical details
An SQL injection vulnerability (CWE-89) in IBM Guardium Data Protection 12.2 allows a remote authenticated attacker to execute arbitrary SQL commands due to improper neutralization of special characters in SQL input. The vulnerability is network-accessible and requires valid authentication credentials to exploit. Successful exploitation could result in unauthorized data access, modification, or deletion.
Affected products
- IBM Guardium Data Protection 12.2
Timeline
- 2026-09-18: disclosed