rootpwn

high · CVSS v3 8.1

CVE-2026-84085

IBM Guardium Data Protection 12.2 contains a command injection vulnerability. A remote attacker can exploit this flaw to execute arbitrary o

Overview

IBM Guardium Data Protection 12.2 contains a command injection vulnerability. A remote attacker can exploit this flaw to execute arbitrary operating system commands. This matters because it threatens the underlying host operating system and database security infrastructure.

Description

IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary OS commands due to improper neutralization of special elements used in an OS command.

Impact

This vulnerability impacts the Confidentiality, Integrity, and Availability of the host system. Successful exploitation allows unauthorized remote attackers to execute arbitrary OS commands with the privileges of the vulnerable application. Enterprise environments relying on Guardium for data security and compliance are at direct risk.

Remediation

Apply the official security updates and patches provided by IBM as soon as they are available. Restrict network access to the administrative and management interfaces of Guardium Data Protection using firewalls or network segmentation. Monitor system and process logs for anomalous command execution patterns indicative of exploitation attempts.

Risk context

The vulnerability is rated as high severity with a CVSS v3 score of 8.1. EPSS data is currently not available. Defenders should treat this as a high-priority risk due to the potential for remote command execution on a critical security appliance.

Affected products

  • IBM Guardium Data Protection 12.2

Scores

Severity
high
CVSS v2
7.6
CVSS v3
8.1
CVSS v4
EPSS

cve-2026-84085 ibm guardium command-injection rce high-severity

← All CVEs