high · CVSS v3 8.1
CVE-2026-84085
IBM Guardium Data Protection 12.2 contains a command injection vulnerability. A remote attacker can exploit this flaw to execute arbitrary o
Overview
IBM Guardium Data Protection 12.2 contains a command injection vulnerability. A remote attacker can exploit this flaw to execute arbitrary operating system commands. This matters because it threatens the underlying host operating system and database security infrastructure.
Description
IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary OS commands due to improper neutralization of special elements used in an OS command.
Impact
This vulnerability impacts the Confidentiality, Integrity, and Availability of the host system. Successful exploitation allows unauthorized remote attackers to execute arbitrary OS commands with the privileges of the vulnerable application. Enterprise environments relying on Guardium for data security and compliance are at direct risk.
Remediation
Apply the official security updates and patches provided by IBM as soon as they are available. Restrict network access to the administrative and management interfaces of Guardium Data Protection using firewalls or network segmentation. Monitor system and process logs for anomalous command execution patterns indicative of exploitation attempts.
Risk context
The vulnerability is rated as high severity with a CVSS v3 score of 8.1. EPSS data is currently not available. Defenders should treat this as a high-priority risk due to the potential for remote command execution on a critical security appliance.
Affected products
- IBM Guardium Data Protection 12.2
Scores
- Severity
- high
- CVSS v2
- 7.6
- CVSS v3
- 8.1
- CVSS v4
- —
- EPSS
- —