critical · CVSS v3 8.1
CVE-2026-84077
IBM Guardium Data Protection 12.2 contains a CSRF flaw that can let a remote attacker bypass security controls. The vulnerability can be exp
Overview
IBM Guardium Data Protection 12.2 contains a CSRF flaw that can let a remote attacker bypass security controls. The vulnerability can be exploited without authentication, enabling privilege escalation or data exfiltration. It is critical and requires immediate attention.
Description
IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to a cross-site request forgery vulnerability.
Impact
The flaw compromises confidentiality, integrity, and availability of protected data. Attackers can gain unauthorized access to sensitive information and modify or delete data. Defenders must consider all Guardium deployments as potentially exposed.
Remediation
Apply the official IBM security patch for Guardium 12.2, or upgrade to a newer version that addresses the CSRF issue. Enable CSRF protection tokens on web interfaces, enforce strict same-site cookie policies, and restrict administrative access to trusted networks. Monitor logs for anomalous cross-site requests.
Risk context
Severity is critical with CVSS v3 score 8.1. No EPSS data available, but the high severity indicates a high risk of exploitation. Defenders should treat this as an urgent patching priority.
Affected products
- IBM Guardium Data Protection 12.2
Scores
- Severity
- critical
- CVSS v2
- 9.4
- CVSS v3
- 8.1
- CVSS v4
- —
- EPSS
- —