critical · CVSS v3 9.6 · EPSS 0.00375
CVE-2026-82832
IBM Guardium Data Protection version 12.2 contains a vulnerability involving improper neutralization of input during web page generation. Th
Overview
IBM Guardium Data Protection version 12.2 contains a vulnerability involving improper neutralization of input during web page generation. This flaw permits a remote authenticated attacker to execute arbitrary code within the affected system. It is critical because successful exploitation compromises the integrity and availability of sensitive database security infrastructure.
Description
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.
Impact
The vulnerability affects the Confidentiality, Integrity, and Availability (CIA) of the system by allowing authenticated remote execution of arbitrary code. Privileged or standard authenticated users with access to the web interface are impacted, potentially leading to full system compromise. Organizations relying on this platform for data security and compliance monitoring face severe operational risks if exploited.
Remediation
Apply the official security patches or updates provided by IBM for Guardium Data Protection 12.2 as soon as they become available. Restrict network access to the administrative web interface to trusted management networks only. Monitor authentication logs and web server access logs for anomalous behavior or unauthorized code execution attempts.
Risk context
Rated as critical with a CVSS v3 score of 9.6, this vulnerability demands prompt attention despite a current low EPSS score of 0.00375. Because remote code execution on a centralized security and compliance platform presents severe enterprise risk, patching should be prioritized during the next maintenance window.
Affected products
- IBM Guardium Data Protection 12.2
Scores
- Severity
- critical
- CVSS v2
- 8.5
- CVSS v3
- 9.6
- CVSS v4
- —
- EPSS
- 0.00375