critical · CVSS v3 9.9
CVE-2026-84075
IBM Guardium Data Protection 12.2 contains a security restriction bypass vulnerability in the ChangeTrackerServlet. The flaw stems from miss
Overview
IBM Guardium Data Protection 12.2 contains a security restriction bypass vulnerability in the ChangeTrackerServlet. The flaw stems from missing authentication controls, which allows remote unauthenticated attackers to access sensitive functionality. This issue is critical as it directly undermines the access control boundaries of a core data security platform.
Description
IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to missing authentication for the ChangeTrackerServlet.
Impact
This vulnerability impacts the confidentiality and integrity of the Guardium Data Protection environment by allowing unauthorized remote access to sensitive components. Organizations relying on this platform for database activity monitoring and compliance are at risk of data exposure or unauthorized configuration visibility. Administrators and security teams responsible for database security governance are directly affected.
Remediation
Apply the official vendor-supplied patches or interim fixes provided by IBM for Guardium Data Protection 12.2. Restrict network access to the administrative and servlet endpoints using firewalls or reverse proxies as a compensating control. Monitor application access logs for anomalous requests targeting the ChangeTrackerServlet.
Risk context
Rated as critical with a CVSS v3 score of 9.9, this vulnerability requires immediate attention due to the potential for unauthenticated remote exploitation against a core security product. EPSS data is not currently available, but the high severity demands prioritization based on exposure.
Affected products
- IBM Guardium Data Protection 12.2
Scores
- Severity
- critical
- CVSS v2
- 9
- CVSS v3
- 9.9
- CVSS v4
- —
- EPSS
- —