high · CVSS v3 7.7
CVE-2026-84105
IBM Guardium Data Protection version 12.2 contains a SQL injection vulnerability that allows remote authenticated attackers to extract sensi
Overview
IBM Guardium Data Protection version 12.2 contains a SQL injection vulnerability that allows remote authenticated attackers to extract sensitive data. The issue stems from insufficient input sanitization before processing database commands within the application. This vulnerability is critical for database security teams because it exposes sensitive organizational data to unauthorized internal or compromised accounts.
Description
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to obtain sensitive information due to improper neutralization of special elements used in an SQL command.
Impact
This vulnerability impacts the Confidentiality of stored database records within the Guardium environment. An authenticated remote attacker can exploit the flaw to view sensitive information they are not authorized to access. Integrity and Availability are not directly impacted, though data theft remains a primary risk.
Remediation
Apply the official vendor-supplied patches or security updates provided by IBM for Guardium Data Protection 12.2. Review and restrict user roles and privileges to ensure the principle of least privilege is enforced for all authenticated accounts. Monitor database query logs for anomalous or unauthorized SQL statements originating from the application.
Risk context
The vulnerability is rated as High severity with a CVSS v3 score of 7.7, indicating a significant risk if exploited. While EPSS data is not currently available, the requirement for authentication means defenders should prioritize fixing this on systems accessible to untrusted or low-privilege users.
Affected products
- IBM Guardium Data Protection 12.2
Scores
- Severity
- high
- CVSS v2
- 6.8
- CVSS v3
- 7.7
- CVSS v4
- —
- EPSS
- —