rootpwn

critical · CVSS v3 9

CVE-2026-84031

IBM Guardium Data Protection 12.2 contains a vulnerability involving improper neutralization of input during web page generation. This flaw

Overview

IBM Guardium Data Protection 12.2 contains a vulnerability involving improper neutralization of input during web page generation. This flaw permits a remote authenticated attacker to execute arbitrary code within the affected system. It matters because successful exploitation compromises the integrity and confidentiality of sensitive database security monitoring infrastructure.

Description

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.

Impact

The vulnerability affects the confidentiality, integrity, and availability of the database security platform. An authenticated remote attacker with specific privileges can execute arbitrary code on the underlying system. Organizations relying on this platform for compliance and data protection face potential system compromise. Privileged users and administrators are the primary entities impacted.

Remediation

Apply the official vendor-supplied patches or security updates provided by IBM for Guardium Data Protection 12.2. Restrict network access to the administrative interfaces to trusted management networks only. Monitor authentication logs and web application traffic for anomalous command execution patterns.

Risk context

This vulnerability is classified as critical with a CVSS v3 score of 9.0, indicating a severe risk to organizational infrastructure. Although EPSS data is not currently available, the high severity warrants immediate prioritization of remediation to prevent unauthorized remote code execution.

Affected products

  • IBM Guardium Data Protection 12.2

Scores

Severity
critical
CVSS v2
9
CVSS v3
9
CVSS v4
EPSS

cve ibm guardium remote-code-execution critical web-application authenticated

← All CVEs