rootpwn

critical · CVSS v3 8.8

CVE-2026-84084

IBM Guardium Data Protection 12.2 contains a cross-site request forgery (CSRF) vulnerability. A remote attacker can exploit this flaw to byp

Overview

IBM Guardium Data Protection 12.2 contains a cross-site request forgery (CSRF) vulnerability. A remote attacker can exploit this flaw to bypass security restrictions and perform unauthorized actions on behalf of a victim. This matters because it compromises the integrity of administrative sessions within a critical database security monitoring platform.

Description

IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to a cross-site request forgery (CSRF) vulnerability.

Impact

This vulnerability primarily impacts the integrity and availability of the IBM Guardium Data Protection environment by allowing unauthorized command execution via authenticated users. Attackers leveraging this flaw can manipulate security settings or system configurations without direct authorization. Organizations relying on this platform for compliance and data monitoring face potential administrative compromise if exploited. Users with active administrative sessions in browser-based interfaces are specifically at risk.

Remediation

Apply the official vendor-supplied patches or security updates provided by IBM for Guardium Data Protection 12.2. Ensure anti-CSRF tokens and SameSite cookie attributes are strictly enforced across all web interfaces. Implement strict session timeout policies and advise users to log out of administrative sessions when not in use.

Risk context

Rated with a critical CVSS v3 score of 8.8, this vulnerability poses a significant risk to enterprise data security environments. While EPSS data is not currently available, the severity demands prompt attention due to the potential for administrative privilege abuse via automated or social engineering vectors.

Affected products

  • IBM Guardium Data Protection 12.2

Scores

Severity
critical
CVSS v2
10
CVSS v3
8.8
CVSS v4
EPSS

CSRF IBM Guardium Web Security Security Bypass Critical

← All CVEs