critical · CVSS v3 9
CVE-2026-84031
IBM Guardium Data Protection 12.2 contains a vulnerability involving improper neutralization of input during web page generation. This flaw
Overview
IBM Guardium Data Protection 12.2 contains a vulnerability involving improper neutralization of input during web page generation. This flaw permits a remote authenticated attacker to execute arbitrary code within the affected system. It matters because successful exploitation compromises the integrity and confidentiality of sensitive database security monitoring infrastructure.
Description
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.
Impact
The vulnerability affects the confidentiality, integrity, and availability of the database security platform. An authenticated remote attacker with specific privileges can execute arbitrary code on the underlying system. Organizations relying on this platform for compliance and data protection face potential system compromise. Privileged users and administrators are the primary entities impacted.
Remediation
Apply the official vendor-supplied patches or security updates provided by IBM for Guardium Data Protection 12.2. Restrict network access to the administrative interfaces to trusted management networks only. Monitor authentication logs and web application traffic for anomalous command execution patterns.
Risk context
This vulnerability is classified as critical with a CVSS v3 score of 9.0, indicating a severe risk to organizational infrastructure. Although EPSS data is not currently available, the high severity warrants immediate prioritization of remediation to prevent unauthorized remote code execution.
Affected products
- IBM Guardium Data Protection 12.2
Scores
- Severity
- critical
- CVSS v2
- 9
- CVSS v3
- 9
- CVSS v4
- —
- EPSS
- —