critical · CVSS v3 9.8
CVE-2026-82967
IBM Guardium Data Protection 12.2 contains an authentication bypass vulnerability within its access control mechanism. This flaw allows unau
Overview
IBM Guardium Data Protection 12.2 contains an authentication bypass vulnerability within its access control mechanism. This flaw allows unauthenticated remote attackers to circumvent IP-based access restrictions and reach the management interface. It matters because it exposes critical database security and monitoring infrastructure to unauthorized external parties.
Description
IBM Guardium Data Protection 12.2 is vulnerable to an authentication bypass that allows an unauthenticated remote attacker to bypass IP-based access controls and access the Guardium management interface.
Impact
The primary impact is a total loss of confidentiality and integrity regarding the management interface access, with potential availability impacts if unauthorized administrative actions are taken. Unauthenticated remote attackers are the primary threat actors, potentially gaining unauthorized visibility into sensitive database activity monitoring controls. Organizations relying solely on IP-based access controls for perimeter defense are directly impacted. This exposure could facilitate deeper reconnaissance or administrative compromise within the data security infrastructure.
Remediation
Apply the official vendor-supplied patches or interim fixes provided by IBM for Guardium Data Protection 12.2. Review network segmentation to ensure the management interface is not exposed directly to untrusted networks or the public internet. Audit authentication logs and access control lists for any anomalous remote access attempts originating from unexpected IP addresses.
Risk context
This vulnerability is rated as critical with a CVSS v3 score of 9.8, indicating severe risk due to the lack of required authentication and remote exploitability. EPSS data is currently unavailable, but the critical severity and direct impact on a management interface warrant immediate prioritization and patching.
Affected products
- IBM Guardium Data Protection 12.2
Scores
- Severity
- critical
- CVSS v2
- 10
- CVSS v3
- 9.8
- CVSS v4
- —
- EPSS
- —