high · CVSS v3 7.6
CVE-2026-84076
IBM Guardium Data Protection version 12.2 contains an improper authorization vulnerability that allows remote authenticated attackers to byp
Overview
IBM Guardium Data Protection version 12.2 contains an improper authorization vulnerability that allows remote authenticated attackers to bypass security restrictions. This flaw affects access control mechanisms within the administrative interface, potentially leading to unauthorized operations. Organizations relying on this platform must address the authorization oversight to maintain data security governance.
Description
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to bypass security restrictions due to improper authorization.
Impact
This vulnerability primarily impacts the integrity and confidentiality of the database security platform by allowing unauthorized actors to perform restricted actions. Authenticated remote users with improper permissions can bypass intended access controls. The impact is significant for enterprises depending on Guardium for centralized database monitoring and compliance.
Remediation
Apply the official security fix or cumulative patch provided by IBM for Guardium Data Protection 12.2. Review and audit user role assignments and access privileges to ensure principle of least privilege is enforced. Monitor administrative access logs for unusual authorization anomalies.
Risk context
The vulnerability is rated as high severity with a CVSS v3 score of 7.6, indicating a serious risk requiring prompt attention. While EPSS data is not currently available, the requirement for authentication is offset by the potential severity of security control bypass in a critical data protection tool.
Affected products
- IBM Guardium Data Protection 12.2
Scores
- Severity
- high
- CVSS v2
- 8
- CVSS v3
- 7.6
- CVSS v4
- —
- EPSS
- —