CVE-2026-84893 PUBLISHED

IBM Guardium Data Protection is affected by multiple vulnerabilities.

Assigner: ibm
Reserved: 02.09.2026 Published: 25.09.2026 Updated: 25.09.2026

IBM Guardium Data Protection 12.2 is vulnerable to SQL injection in the PESI service. An authenticated attacker could exploit this vulnerability to access sensitive information in the internal database.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L
CVSS Score: 7.6

Product Status

Vendor IBM
Product Guardium Data Protection
Versions
  • Version 12.2 is affected

Solutions

IBM encourages customers to update their systems promptly.

ProductVersions FixIBM Guardium Data Protection12.2 https://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Security&product=ibm/Information+Management/InfoSphere+Guardium&release=12.2&platform=Linux&function=fixId&fixids=SqlGuard_12.0p233_FixPack&includeSupersedes=0&source=fc

References

Problem Types

  • CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') CWE