rootpwn

critical · CVSS v3 9.8 · EPSS 0.00511

CVE-2026-82340

IBM Guardium Data Protection 12.2 contains an insecure deserialization and reflective method dispatch vulnerability in the Change Audit Syst

Overview

IBM Guardium Data Protection 12.2 contains an insecure deserialization and reflective method dispatch vulnerability in the Change Audit System listener. An unauthenticated network attacker reaching TCP port 16017 can submit crafted serialized messages. This issue matters because it can potentially lead to unintended code execution on the appliance.

Description

IBM Guardium Data Protection 12.2 is vulnerable to unauthenticated insecure deserialization and attacker-controlled reflective method dispatch in the Change Audit System (CAS) listener. A network attacker able to reach TCP port 16017 may submit crafted serialized messages and potentially cause unintended code execution in the Guardium appliance.

Impact

This critical vulnerability threatens the Confidentiality, Integrity, and Availability of the affected database security appliance. Organizations utilizing the vulnerable version risk total system compromise if network access to the listener is not properly restricted. The impact is severe due to the unauthenticated nature of the flaw.

Remediation

Apply the official security patches or updates provided by IBM for Guardium Data Protection 12.2. Restrict network access to TCP port 16017 using firewalls or security groups to ensure only trusted internal management paths can reach the Change Audit System listener.

Risk context

Rated as critical with a CVSS v3 score of 9.8, indicating the highest severity level for potential system compromise. While the current EPSS score of 0.00511 is relatively low, the combination of unauthenticated remote access and critical impact demands prompt prioritization and mitigation.

Affected products

  • IBM Guardium Data Protection 12.2

Scores

Severity
critical
CVSS v2
10
CVSS v3
9.8
CVSS v4
EPSS
0.00511

insecure-deserialization remote-code-execution ibm-guardium critical-severity network-attack defensive-guidance

← All CVEs