rootpwn

high · CVSS v3 7.6

CVE-2026-84076

IBM Guardium Data Protection version 12.2 contains an improper authorization vulnerability that allows remote authenticated attackers to byp

Overview

IBM Guardium Data Protection version 12.2 contains an improper authorization vulnerability that allows remote authenticated attackers to bypass security restrictions. This flaw affects access control mechanisms within the administrative interface, potentially leading to unauthorized operations. Organizations relying on this platform must address the authorization oversight to maintain data security governance.

Description

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to bypass security restrictions due to improper authorization.

Impact

This vulnerability primarily impacts the integrity and confidentiality of the database security platform by allowing unauthorized actors to perform restricted actions. Authenticated remote users with improper permissions can bypass intended access controls. The impact is significant for enterprises depending on Guardium for centralized database monitoring and compliance.

Remediation

Apply the official security fix or cumulative patch provided by IBM for Guardium Data Protection 12.2. Review and audit user role assignments and access privileges to ensure principle of least privilege is enforced. Monitor administrative access logs for unusual authorization anomalies.

Risk context

The vulnerability is rated as high severity with a CVSS v3 score of 7.6, indicating a serious risk requiring prompt attention. While EPSS data is not currently available, the requirement for authentication is offset by the potential severity of security control bypass in a critical data protection tool.

Affected products

  • IBM Guardium Data Protection 12.2

Scores

Severity
high
CVSS v2
8
CVSS v3
7.6
CVSS v4
EPSS

IBM Guardium Authorization Bypass Access Control High Severity Data Protection

← All CVEs