rootpwn

critical · CVSS v3 8.8

CVE-2026-84034

IBM Guardium Data Protection 12.2 contains a hardcoded credentials vulnerability located within the hardware_assess and obstore binaries. Th

Overview

IBM Guardium Data Protection 12.2 contains a hardcoded credentials vulnerability located within the hardware_assess and obstore binaries. This flaw allows a low-privileged authenticated user to recover hardcoded product master secrets. Consequently, it can lead to unauthorized access to the internal database and exposure of sensitive system information.

Description

IBM Guardium Data Protection 12.2 is vulnerable to a hardcoded credentials vulnerability in the hardware_assess/obstore binaries. A low-privileged authenticated user can recover hardcoded product master secrets, potentially resulting in unauthorized access to the internal database and compromise of sensitive system information.

Impact

Confidentiality and integrity are impacted, as attackers can extract master secrets and gain unauthorized database access. Availability may also be affected if sensitive system configurations are modified. The victims are organizations utilizing the affected IBM Guardium deployment where internal users hold low-privileged access.

Remediation

Apply the official vendor patch or security update provided by IBM for Guardium Data Protection 12.2. Restrict internal access controls and monitor authentication logs for anomalous privilege escalation or database access patterns.

Risk context

The vulnerability is rated as critical with a CVSS v3 score of 8.8, indicating a high potential severity for affected environments. Immediate patching and credential rotation should be prioritized to mitigate exposure.

Affected products

  • IBM Guardium Data Protection 12.2

Scores

Severity
critical
CVSS v2
9
CVSS v3
8.8
CVSS v4
EPSS

hardcoded-credentials unauthorized-access database-security privilege-abuse ibm-guardium

← All CVEs