Executive brief
IBM Guardium Data Protection is a data security platform that monitors and protects databases in enterprise environments. An authenticated attacker can inject malicious code through a web interface that executes in the context of other users' sessions, potentially leading to complete compromise of the system including data theft, unauthorized modifications, and service disruption.
Technical details
The vulnerability is an improper neutralization of input during web page generation (CWE-79: Cross-site Scripting) in IBM Guardium Data Protection 12.2. An authenticated remote attacker can inject arbitrary code that executes in victim browsers, requiring user interaction (UI:R). Successful exploitation allows an attacker to hijack admin sessions, steal credentials, or modify security policies.
Affected products
- IBM Guardium Data Protection 12.2
Timeline
- 2026-09-18: disclosed