critical · CVSS v3 9.9
CVE-2026-84064
IBM Guardium Data Protection 12.2 contains an SQL injection vulnerability in its remote authenticated interface. This flaw allows malicious
Overview
IBM Guardium Data Protection 12.2 contains an SQL injection vulnerability in its remote authenticated interface. This flaw allows malicious actors to manipulate database queries, potentially leading to unauthorized data access or modification. Because the vulnerability affects a core data security platform, its compromise poses severe risks to enterprise data integrity.
Description
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary SQL commands due to improper neutralization of special elements used in an SQL command.
Impact
The vulnerability impacts the Confidentiality, Integrity, and Availability of the underlying database systems managed by Guardium. Organizations relying on this platform face risks of data exposure, unauthorized modification, and potential operational disruption. Specifically, remote authenticated attackers can leverage this flaw to execute arbitrary SQL commands.
Remediation
Apply the official security patches or updates provided by IBM for Guardium Data Protection 12.2. Restrict access to administrative and authenticated interfaces to trusted network segments and authorized personnel only. Monitor database audit logs for unusual query patterns and unexpected administrative database activity.
Risk context
This vulnerability is rated as critical with a CVSS v3 score of 9.9, indicating an extremely high potential impact on enterprise environments. Defenders should prioritize immediate patching and access control hardening for all affected IBM Guardium instances.
Affected products
- IBM Guardium Data Protection 12.2
Scores
- Severity
- critical
- CVSS v2
- 9
- CVSS v3
- 9.9
- CVSS v4
- —
- EPSS
- —