high · CVSS v3 7.6
CVE-2026-84239
IBM Guardium Data Protection 12.2 contains an SQL injection flaw that can be exploited by authenticated users to retrieve sensitive data. Th
Overview
IBM Guardium Data Protection 12.2 contains an SQL injection flaw that can be exploited by authenticated users to retrieve sensitive data. The vulnerability arises from improper neutralization of special characters in SQL commands. It allows attackers to read confidential information stored in the system.
Description
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to obtain sensitive information due to improper neutralization of special elements used in an SQL command.
Impact
Confidentiality is compromised as attackers can access protected data. Availability is not directly affected, but integrity may be at risk if data is modified. The primary impact is on the security posture of organizations using Guardium for data protection.
Remediation
Apply the latest security patch or upgrade to a newer version of Guardium Data Protection. Enforce least privilege for database accounts and restrict authentication to trusted users. Monitor database logs for suspicious query patterns and implement input validation or parameterized queries where possible.
Risk context
Severity is high with a CVSS v3 score of 7.6. No EPSS data is available, but the vulnerability is exploitable by authenticated users, making it a significant risk for organizations that have not yet patched.
Affected products
- IBM Guardium Data Protection 12.2
Scores
- Severity
- high
- CVSS v2
- 6.8
- CVSS v3
- 7.6
- CVSS v4
- —
- EPSS
- —