high · CVSS v3 8.9
CVE-2026-84074
IBM Guardium Data Protection 12.2 contains a vulnerability that allows remote authenticated attackers to execute arbitrary code. The issue a
Overview
IBM Guardium Data Protection 12.2 contains a vulnerability that allows remote authenticated attackers to execute arbitrary code. The issue arises from improper neutralization of input during web page generation. This matters because successful exploitation could lead to unauthorized code execution within the administrative context.
Description
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.
Impact
This vulnerability impacts the integrity and availability of the affected system, potentially leading to a complete compromise of confidentiality. Administrators and organizations utilizing the Guardium platform are at risk if attackers obtain valid credentials. The primary impact is unauthorized remote code execution by an authenticated user.
Remediation
Apply the official vendor patches or updates provided by IBM for Guardium Data Protection 12.2. Restrict administrative access to trusted personnel and enforce strict multi-factor authentication. Monitor web application logs for unusual input patterns or unexpected execution behaviors.
Risk context
Rated as a high severity vulnerability with a CVSS v3 score of 8.9, this issue requires prompt attention despite the lack of current EPSS metrics. Defenders should prioritize patching based on the authenticated vector requirement and potential for code execution.
Affected products
- IBM Guardium Data Protection 12.2
Scores
- Severity
- high
- CVSS v2
- 8.7
- CVSS v3
- 8.9
- CVSS v4
- —
- EPSS
- —