critical · CVSS v3 8.8
CVE-2026-84084
IBM Guardium Data Protection 12.2 contains a cross-site request forgery (CSRF) vulnerability. A remote attacker can exploit this flaw to byp
Overview
IBM Guardium Data Protection 12.2 contains a cross-site request forgery (CSRF) vulnerability. A remote attacker can exploit this flaw to bypass security restrictions and perform unauthorized actions on behalf of a victim. This matters because it compromises the integrity of administrative sessions within a critical database security monitoring platform.
Description
IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to a cross-site request forgery (CSRF) vulnerability.
Impact
This vulnerability primarily impacts the integrity and availability of the IBM Guardium Data Protection environment by allowing unauthorized command execution via authenticated users. Attackers leveraging this flaw can manipulate security settings or system configurations without direct authorization. Organizations relying on this platform for compliance and data monitoring face potential administrative compromise if exploited. Users with active administrative sessions in browser-based interfaces are specifically at risk.
Remediation
Apply the official vendor-supplied patches or security updates provided by IBM for Guardium Data Protection 12.2. Ensure anti-CSRF tokens and SameSite cookie attributes are strictly enforced across all web interfaces. Implement strict session timeout policies and advise users to log out of administrative sessions when not in use.
Risk context
Rated with a critical CVSS v3 score of 8.8, this vulnerability poses a significant risk to enterprise data security environments. While EPSS data is not currently available, the severity demands prompt attention due to the potential for administrative privilege abuse via automated or social engineering vectors.
Affected products
- IBM Guardium Data Protection 12.2
Scores
- Severity
- critical
- CVSS v2
- 10
- CVSS v3
- 8.8
- CVSS v4
- —
- EPSS
- —