GHSA-g38r-cx9q-54vqCriticalCVSS 9.8

IBM Guardium Data Protection 12.2 is vulnerable to an unauthenticated second-order SQL injection...

Published
September 18, 2026
Last Modified
September 18, 2026

🔗 CVE IDs covered (1)

📋 Description

IBM Guardium Data Protection 12.2 is vulnerable to an unauthenticated second-order SQL injection vulnerability in the generateInsertQuery functionality of change-tracker-data.sql. A remote attacker could inject malicious SQL that is subsequently processed by the application, potentially resulting in compromise of the confidentiality, integrity, and availability of the affected system.

🔗 References (3)