CVE-2026-81933: IBM Guardium Data Protection is affected by multiple vulnerabilities.
IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability in the Analytic Grid Service Handler. A low-privileged authenticated user can inject SQL statements through the analytic cases grid endpoint, potentially resulting in unauthorized access to sensitive data and impact to the confidentiality, integrity, and availability of the affected system.
Other sources
IBM Security Guardium is vulnerable to a SQL injection vulnerability in the Analytic Grid Service Handler. A low-privileged authenticated user can inject SQL statements through the analytic cases grid endpoint, potentially resulting in unauthorized access to sensitive data and impact to the confidentiality, integrity, and availability of the affected system.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Guardium Data Protectionto a version that resolves this vulnerability.Fixed in 12.2Patch SqlGuard_12.0p233_FixPack - Upgrade
Upgrade
IBM Security Guardiumto a version that resolves this vulnerability.Fixed in 12.2Patch SqlGuard_12.0p233_FixPack
Event History
Frequently Asked Questions
Who can exploit this vulnerability?
Exploitation requires a low-privileged authenticated user. The vulnerable attack surface is the analytic cases grid endpoint handled by the Analytic Grid Service Handler.
What could an attacker achieve?
An attacker may inject SQL statements and gain unauthorized access to sensitive data. The issue may affect the confidentiality, integrity, and availability of the affected system.