rootpwn

critical · CVSS v3 9.8

CVE-2026-80441

IBM Guardium Data Protection 12.2 is vulnerable to an unauthenticated second-order SQL injection vulnerability in the ge…

Description

IBM Guardium Data Protection 12.2 is vulnerable to an unauthenticated second-order SQL injection vulnerability in the generateInsertQuery functionality of change-tracker-data.sql. A remote attacker could inject malicious SQL that is subsequently processed by the application, potentially resulting in compromise of the confidentiality, integrity, and availability of the affected system.

Scores

Severity
critical
CVSS v2
10
CVSS v3
9.8
CVSS v4
EPSS

← All CVEs