CyberRota Analysis
AI-GeneratedIBM Guardium Data Protection 12.2 is susceptible to a critical unauthenticated second-order SQL injection vulnerability in the generateInsertQuery function, allowing remote attackers to execute malicious SQL commands. This could lead to severe impacts on the confidentiality, integrity, and availability of the system. Organizations using this version of Guardium should prioritize immediate remediation to mitigate potential exploitation risks.
Original NVD Description
IBM Guardium Data Protection 12.2 is vulnerable to an unauthenticated second-order SQL injection vulnerability in the generateInsertQuery functionality of change-tracker-data.sql. A remote attacker could inject malicious SQL that is subsequently processed by the application, potentially resulting in compromise of the confidentiality, integrity, and availability of the affected system.
Related CVEs
Other vulnerabilities affecting the same vendor(s)