rootpwn

high · CVSS v3 7.6

CVE-2026-82896

IBM Guardium Data Protection 12.2 contains a path traversal vulnerability that allows remote authenticated attackers to access unauthorized

Overview

IBM Guardium Data Protection 12.2 contains a path traversal vulnerability that allows remote authenticated attackers to access unauthorized directories on the underlying system. This flaw matters because it exposes sensitive system files and compromises the data integrity of the security platform.

Description

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to traverse directories on the system due to a path traversal vulnerability.

Impact

This vulnerability impacts confidentiality by potentially exposing sensitive system files to authenticated users with improper access. It affects administrators and enterprise environments relying on Guardium for data security. The integrity of the host operating system could also be compromised if critical files are read or manipulated.

Remediation

Apply the official vendor-supplied patches or security updates provided by IBM for Guardium Data Protection 12.2. Restrict user privileges and enforce the principle of least privilege for authenticated accounts. Monitor system logs for unauthorized directory access attempts and abnormal file traversal patterns.

Risk context

Rated as a high severity vulnerability with a CVSS v3 score of 7.6, requiring prompt patching by security teams managing IBM Guardium deployments. While EPSS data is not present, the requirement for authentication is a mitigating factor that limits exposure to internal or compromised credentials.

Affected products

  • IBM Guardium Data Protection 12.2

Scores

Severity
high
CVSS v2
8
CVSS v3
7.6
CVSS v4
EPSS

path-traversal ibm guardium high-severity authenticated directory-traversal data-protection

← All CVEs