Executive brief
IBM Guardium Data Protection is a security monitoring system that tracks and protects database access. An authenticated attacker could exploit improper SQL query handling to extract sensitive information from the system's database without authorization. This could expose credentials, audit logs, and other confidential data stored in Guardium.
Technical details
A SQL injection vulnerability exists in IBM Guardium Data Protection 12.2 due to improper neutralization of special SQL elements, allowing a remote authenticated attacker to craft malicious SQL queries. The vulnerability requires valid authentication credentials and network access to the Guardium interface. Successful exploitation enables attackers to read arbitrary data from the underlying database, potentially including sensitive authentication credentials and compliance audit records.
Affected products
- IBM Guardium Data Protection 12.2
Timeline
- 2026-09-18: disclosed