rootpwn

high · CVSS v3 7.4

CVE-2026-84036

IBM Guardium Data Protection 12.2 contains an improper authorization vulnerability. A remote authenticated attacker can exploit this flaw to

Overview

IBM Guardium Data Protection 12.2 contains an improper authorization vulnerability. A remote authenticated attacker can exploit this flaw to bypass security restrictions. This matters because it compromises access controls within sensitive data security environments.

Description

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to bypass security restrictions due to improper authorization.

Impact

This vulnerability impacts confidentiality, integrity, and availability by allowing unauthorized access to restricted features or data. Remote authenticated users are primarily affected, as they can escalate privileges or bypass intended operational boundaries.

Remediation

Apply the latest security patches and updates provided by IBM for Guardium Data Protection 12.2. Review and audit user role assignments and authorization policies to ensure least-privilege enforcement.

Risk context

Rated with a high severity CVSS v3 score of 7.4, this vulnerability requires timely remediation despite the lack of a published EPSS score due to the sensitive nature of data protection platforms.

Affected products

  • IBM Guardium Data Protection 12.2

Scores

Severity
high
CVSS v2
6.5
CVSS v3
7.4
CVSS v4
EPSS

IBM Guardium Authorization Bypass High Severity Access Control

← All CVEs