SQL Command Injection Vulnerability in IBM Guardium Data Protection by IBM
CVE-2026-84239

7.6HIGH

Key Information:

Vendor

IBM

Vendor
CVE Published:
18 September 2026

What is CVE-2026-84239?

IBM Guardium Data Protection 12.2 features a vulnerability that may be exploited by remote authenticated attackers to retrieve sensitive information. This is attributed to the improper handling of special characters in SQL commands, which could allow unauthorized access to confidential data. Organizations using this version are advised to apply necessary patches and review their security policies to mitigate potential risks associated with this vulnerability. For more information, refer to the vendor advisory.

Affected Version(s)

Guardium Data Protection 12.2

References

CVSS V3.1

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.