rootpwn

critical · CVSS v3 9.8

CVE-2026-84082

IBM Guardium Data Protection 12.2 contains a critical SQL injection vulnerability in remote database query processing. This flaw allows unau

Overview

IBM Guardium Data Protection 12.2 contains a critical SQL injection vulnerability in remote database query processing. This flaw allows unauthorized remote attackers to execute arbitrary SQL commands against the underlying database. It matters because successful exploitation could lead to complete compromise of sensitive enterprise data managed by the platform.

Description

IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary SQL commands due to improper neutralization of special elements used in an SQL command.

Impact

This vulnerability impacts the confidentiality, integrity, and availability of the database backend. Unauthorized users may extract, alter, or delete sensitive data and potentially disrupt security monitoring operations. Organizations relying on this appliance for compliance and database activity monitoring are directly exposed to severe data breaches.

Remediation

Apply the official security patches or updates provided by IBM for Guardium Data Protection 12.2 immediately. Review database activity logs for unusual query patterns or anomalous administrative access. Restrict network access to management and data interfaces to trusted administrative segments only.

Risk context

Rated as critical with a CVSS score of 9.8, this vulnerability represents an extremely high risk due to the potential for unauthenticated remote code execution within the database layer. Remediation should be prioritized immediately upon vendor patch availability.

Affected products

  • IBM Guardium Data Protection 12.2

Scores

Severity
critical
CVSS v2
10
CVSS v3
9.8
CVSS v4
EPSS

cve sql-injection ibm guardium critical remote-execution database-security

← All CVEs