Executive brief
IBM Guardium Data Protection is a database security monitoring system used to protect sensitive data in corporate environments. An authenticated attacker can inject malicious SQL commands to extract sensitive information from monitored databases. This allows an insider with legitimate access to bypass security controls and exfiltrate confidential data.
Technical details
SQL injection vulnerability (CWE-89) in IBM Guardium Data Protection 12.2 allowing authenticated remote attackers to execute arbitrary SQL queries. The vulnerability exists due to improper neutralization of special characters in SQL command construction, requiring valid authentication credentials and network access. Successful exploitation leads to information disclosure of sensitive database contents.
Affected products
- IBM Guardium Data Protection 12.2
Timeline
- 2026-09-18: disclosed