{"id":"CVE-2026-81656","published":"2026-09-18T20:17:23.867","lastModified":"2026-09-23T04:17:48.570","description":"IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability in the New Query Builder REST Processor. A low-privileged authenticated user can inject SQL statements through the newQueryBuilder REST endpoint, potentially resulting in unauthorized access to data and impact to the confidentiality, integrity, and availability of the affected system.","cvssScore":8.8,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-89"],"vendors":[],"products":[],"references":[{"url":"https://www.ibm.com/support/pages/node/7288040","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The flaw allows a low-privileged authenticated user to inject SQL statements, potentially leading to unauthorized data access and system impact.","exploitability":"Exploitation requires a low-privileged authenticated user and knowledge of the newQueryBuilder REST endpoint; the vulnerability is relatively easy to exploit given these preconditions.","blast_radius":"If exploited, the vulnerability could result in unauthorized access to sensitive data, compromising confidentiality, integrity, and availability of the system.","remediation":"Upgrade to IBM Guardium Data Protection 12.2 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["sql-injection","auth-bypass","web"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-30T09:08:35.672Z"}}