high · CVSS v3 8.9
CVE-2026-84070
IBM Guardium Data Protection 12.2 is vulnerable to remote code execution via improper input sanitization in web page generation. Attackers w
Overview
IBM Guardium Data Protection 12.2 is vulnerable to remote code execution via improper input sanitization in web page generation. Attackers who can authenticate to the system can exploit this flaw to run arbitrary code. This flaw could allow attackers to compromise the integrity, confidentiality, and availability of protected data.
Description
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.
Impact
The vulnerability allows authenticated attackers to execute arbitrary code, compromising confidentiality, integrity, and availability of the protected data and the Guardium system itself. Defenders must consider that privileged users or compromised credentials could be used to exploit the flaw, potentially leading to full system compromise.
Remediation
Apply the latest security patch released by IBM for Guardium Data Protection 12.2 that addresses input sanitization in web page generation. If patching is not immediately possible, restrict web interface access to trusted networks, enforce least privilege for user accounts, and monitor for suspicious activity such as unexpected code execution or unauthorized configuration changes.
Risk context
Severity is high with CVSS v3 score 8.9. No EPSS data available. The flaw is exploitable by authenticated users, making it a significant risk for organizations running Guardium 12.2.
Affected products
- IBM Guardium Data Protection 12.2
Scores
- Severity
- high
- CVSS v2
- 8.7
- CVSS v3
- 8.9
- CVSS v4
- —
- EPSS
- —