rootpwn

critical · CVSS v3 9.9

CVE-2026-84078

IBM Guardium Data Protection 12.2 contains a missing authentication vulnerability in the LoadBalancerServlet. This flaw allows unauthenticat

Overview

IBM Guardium Data Protection 12.2 contains a missing authentication vulnerability in the LoadBalancerServlet. This flaw allows unauthenticated attackers to access privileged load-balancer operations over the network. It matters because successful exploitation compromises system integrity and availability.

Description

IBM Guardium Data Protection 12.2 is vulnerable to a missing authentication vulnerability in the LoadBalancerServlet. An unauthenticated user can access privileged load-balancer operations, potentially resulting in unauthorized actions and impact to the integrity and availability of the affected system.

Impact

The vulnerability affects system integrity and availability by allowing unauthorized execution of privileged operations. Unauthenticated remote attackers can disrupt database security monitoring workflows and system functions. Organizations relying on this platform for compliance and data protection face potential service degradation and unauthorized administrative control.

Remediation

Apply the official security patches or updates provided by IBM for Guardium Data Protection 12.2. Restrict network access to management and load-balancer interfaces using firewalls or network segmentation. Monitor access logs for unauthorized requests targeting the LoadBalancerServlet endpoint.

Risk context

Rated as critical with a CVSS v3 score of 9.9, this vulnerability poses a severe risk due to the lack of authentication required for exploitation. Defenders should prioritize immediate patching and network boundary enforcement.

Affected products

  • IBM Guardium Data Protection 12.2

Scores

Severity
critical
CVSS v2
9
CVSS v3
9.9
CVSS v4
EPSS

IBM Guardium Missing Authentication Critical Data Protection Network Security

← All CVEs