Summary
CVE-2026-84209 is a SQL injection vulnerability (CWE-89) in IBM Guardium Data Protection. A remote attacker could execute arbitrary SQL commands because of improper neutralization of special elements in an SQL command. It is rated High severity (CVSS 8.1).
Technical details
- Root cause: improper neutralization of special elements used in an SQL command (CWE-89).
- Attack vector: network, with no privileges and no user interaction required. Attack complexity is rated High.
- Impact: arbitrary SQL command execution by a remote attacker. The CVSS vector rates confidentiality, integrity and availability impact as High.
- The IBM bulletin does not publish further details on the vulnerable component or on exploitation.
Affected software
- IBM Guardium Data Protection 12.1 (Guardium appliance)
- IBM Guardium Data Protection 12.2.2 (Edge component)
Severity
CVSS v3.1 base score 8.1 (High): CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: apply IBM Guardium Data Protection patch 12.0p147 (appliance) or Edge patch 12.0p15004 (Edge), both available through IBM Fix Central.
- Workarounds: none are documented in the IBM bulletin. Until patching is complete, restrict network access to Guardium management interfaces to trusted networks.

