high · CVSS v3 7.4
CVE-2026-84036
IBM Guardium Data Protection 12.2 contains an improper authorization vulnerability. A remote authenticated attacker can exploit this flaw to
Overview
IBM Guardium Data Protection 12.2 contains an improper authorization vulnerability. A remote authenticated attacker can exploit this flaw to bypass security restrictions. This matters because it compromises access controls within sensitive data security environments.
Description
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to bypass security restrictions due to improper authorization.
Impact
This vulnerability impacts confidentiality, integrity, and availability by allowing unauthorized access to restricted features or data. Remote authenticated users are primarily affected, as they can escalate privileges or bypass intended operational boundaries.
Remediation
Apply the latest security patches and updates provided by IBM for Guardium Data Protection 12.2. Review and audit user role assignments and authorization policies to ensure least-privilege enforcement.
Risk context
Rated with a high severity CVSS v3 score of 7.4, this vulnerability requires timely remediation despite the lack of a published EPSS score due to the sensitive nature of data protection platforms.
Affected products
- IBM Guardium Data Protection 12.2
Scores
- Severity
- high
- CVSS v2
- 6.5
- CVSS v3
- 7.4
- CVSS v4
- —
- EPSS
- —