rootpwn

critical · CVSS v3 8.1

CVE-2026-84077

IBM Guardium Data Protection 12.2 contains a CSRF flaw that can let a remote attacker bypass security controls. The vulnerability can be exp

Overview

IBM Guardium Data Protection 12.2 contains a CSRF flaw that can let a remote attacker bypass security controls. The vulnerability can be exploited without authentication, enabling privilege escalation or data exfiltration. It is critical and requires immediate attention.

Description

IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to a cross-site request forgery vulnerability.

Impact

The flaw compromises confidentiality, integrity, and availability of protected data. Attackers can gain unauthorized access to sensitive information and modify or delete data. Defenders must consider all Guardium deployments as potentially exposed.

Remediation

Apply the official IBM security patch for Guardium 12.2, or upgrade to a newer version that addresses the CSRF issue. Enable CSRF protection tokens on web interfaces, enforce strict same-site cookie policies, and restrict administrative access to trusted networks. Monitor logs for anomalous cross-site requests.

Risk context

Severity is critical with CVSS v3 score 8.1. No EPSS data available, but the high severity indicates a high risk of exploitation. Defenders should treat this as an urgent patching priority.

Affected products

  • IBM Guardium Data Protection 12.2

Scores

Severity
critical
CVSS v2
9.4
CVSS v3
8.1
CVSS v4
EPSS

CSRF IBM Guardium Data Protection Critical Remote Exploit Privilege Escalation

← All CVEs