Executive brief
IBM Guardium Data Protection is database security software that monitors and protects sensitive data. A vulnerability in web page generation could allow remote attackers to inject and execute arbitrary code, potentially compromising the entire database security system and gaining access to protected data.
Technical details
Improper neutralization of input during web page generation (CWE-79) allows unauthenticated remote attackers to inject malicious input that is executed as code in the web interface. The vulnerability requires no special privileges and exploits the web application's failure to properly sanitize user-supplied data before rendering it in responses.
Affected products
- IBM Guardium Data Protection 12.2
Timeline
- 2026-09-18: disclosed