← Back to search

CVE-2026-80441

9.8 CRITICAL

Published 2026-09-18 · Updated 2026-09-23

AI risk analysis

Summary
The flaw is an unauthenticated second-order SQL injection vulnerability in IBM Guardium Data Protection 12.2, allowing remote attackers to inject malicious SQL and potentially compromise the system’s confidentiality, integrity, and availability.
Exploitability
Exploitation is relatively straightforward given the unauthenticated nature and the specific SQL injection point in the change-tracker-data.sql functionality.
Blast radius
If exploited, the vulnerability could result in a complete compromise of the affected system, including data theft, corruption, and service disruption.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to IBM Guardium Data Protection 12.2.1 or later.
sql-injectionunauthenticateddata-compromise

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

IBM Guardium Data Protection 12.2 is vulnerable to an unauthenticated second-order SQL injection vulnerability in the generateInsertQuery functionality of change-tracker-data.sql. A remote attacker could inject malicious SQL that is subsequently processed by the application, potentially resulting in compromise of the confidentiality, integrity, and availability of the affected system.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-89

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.