critical · CVSS v3 9.8
CVE-2026-84082
IBM Guardium Data Protection 12.2 contains a critical SQL injection vulnerability in remote database query processing. This flaw allows unau
Overview
IBM Guardium Data Protection 12.2 contains a critical SQL injection vulnerability in remote database query processing. This flaw allows unauthorized remote attackers to execute arbitrary SQL commands against the underlying database. It matters because successful exploitation could lead to complete compromise of sensitive enterprise data managed by the platform.
Description
IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary SQL commands due to improper neutralization of special elements used in an SQL command.
Impact
This vulnerability impacts the confidentiality, integrity, and availability of the database backend. Unauthorized users may extract, alter, or delete sensitive data and potentially disrupt security monitoring operations. Organizations relying on this appliance for compliance and database activity monitoring are directly exposed to severe data breaches.
Remediation
Apply the official security patches or updates provided by IBM for Guardium Data Protection 12.2 immediately. Review database activity logs for unusual query patterns or anomalous administrative access. Restrict network access to management and data interfaces to trusted administrative segments only.
Risk context
Rated as critical with a CVSS score of 9.8, this vulnerability represents an extremely high risk due to the potential for unauthenticated remote code execution within the database layer. Remediation should be prioritized immediately upon vendor patch availability.
Affected products
- IBM Guardium Data Protection 12.2
Scores
- Severity
- critical
- CVSS v2
- 10
- CVSS v3
- 9.8
- CVSS v4
- —
- EPSS
- —