rootpwn

high · CVSS v3 8.9

CVE-2026-84070

IBM Guardium Data Protection 12.2 is vulnerable to remote code execution via improper input sanitization in web page generation. Attackers w

Overview

IBM Guardium Data Protection 12.2 is vulnerable to remote code execution via improper input sanitization in web page generation. Attackers who can authenticate to the system can exploit this flaw to run arbitrary code. This flaw could allow attackers to compromise the integrity, confidentiality, and availability of protected data.

Description

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.

Impact

The vulnerability allows authenticated attackers to execute arbitrary code, compromising confidentiality, integrity, and availability of the protected data and the Guardium system itself. Defenders must consider that privileged users or compromised credentials could be used to exploit the flaw, potentially leading to full system compromise.

Remediation

Apply the latest security patch released by IBM for Guardium Data Protection 12.2 that addresses input sanitization in web page generation. If patching is not immediately possible, restrict web interface access to trusted networks, enforce least privilege for user accounts, and monitor for suspicious activity such as unexpected code execution or unauthorized configuration changes.

Risk context

Severity is high with CVSS v3 score 8.9. No EPSS data available. The flaw is exploitable by authenticated users, making it a significant risk for organizations running Guardium 12.2.

Affected products

  • IBM Guardium Data Protection 12.2

Scores

Severity
high
CVSS v2
8.7
CVSS v3
8.9
CVSS v4
EPSS

remote-code-execution input-sanitization web-application IBM Guardium high-severity

← All CVEs