critical · CVSS v3 8.8
CVE-2026-84034
IBM Guardium Data Protection 12.2 contains a hardcoded credentials vulnerability located within the hardware_assess and obstore binaries. Th
Overview
IBM Guardium Data Protection 12.2 contains a hardcoded credentials vulnerability located within the hardware_assess and obstore binaries. This flaw allows a low-privileged authenticated user to recover hardcoded product master secrets. Consequently, it can lead to unauthorized access to the internal database and exposure of sensitive system information.
Description
IBM Guardium Data Protection 12.2 is vulnerable to a hardcoded credentials vulnerability in the hardware_assess/obstore binaries. A low-privileged authenticated user can recover hardcoded product master secrets, potentially resulting in unauthorized access to the internal database and compromise of sensitive system information.
Impact
Confidentiality and integrity are impacted, as attackers can extract master secrets and gain unauthorized database access. Availability may also be affected if sensitive system configurations are modified. The victims are organizations utilizing the affected IBM Guardium deployment where internal users hold low-privileged access.
Remediation
Apply the official vendor patch or security update provided by IBM for Guardium Data Protection 12.2. Restrict internal access controls and monitor authentication logs for anomalous privilege escalation or database access patterns.
Risk context
The vulnerability is rated as critical with a CVSS v3 score of 8.8, indicating a high potential severity for affected environments. Immediate patching and credential rotation should be prioritized to mitigate exposure.
Affected products
- IBM Guardium Data Protection 12.2
Scores
- Severity
- critical
- CVSS v2
- 9
- CVSS v3
- 8.8
- CVSS v4
- —
- EPSS
- —