rootpwn

high · CVSS v3 7.2

CVE-2026-84086

IBM Guardium Data Protection 12.2 contains a path traversal vulnerability that allows remote authenticated attackers to execute arbitrary co

Overview

IBM Guardium Data Protection 12.2 contains a path traversal vulnerability that allows remote authenticated attackers to execute arbitrary code. The flaw exists due to improper restriction of pathnames to a designated directory. This matters because it could lead to unauthorized system compromise within the database security environment.

Description

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper limitation of a pathname to a restricted directory.

Impact

This vulnerability impacts the integrity and availability of the affected system, potentially leading to complete system compromise. Confidentiality is also at risk as attackers could access sensitive database monitoring and security configurations. The impact is restricted to remote authenticated users with specific permissions within the application.

Remediation

Apply the latest official security patches and updates provided by IBM for Guardium Data Protection 12.2. Restrict user privileges and enforce the principle of least privilege to minimize potential abuse of administrative functions. Monitor authentication logs and system activity for unusual path traversal patterns or unauthorized command execution.

Risk context

The vulnerability carries a CVSS v3 base score of 7.2, designating it as a high-severity issue. Although EPSS data is not currently available, remediation should be prioritized due to the potential for arbitrary code execution on a critical security platform.

Affected products

  • IBM Guardium Data Protection 12.2

Scores

Severity
high
CVSS v2
8.3
CVSS v3
7.2
CVSS v4
EPSS

path-traversal remote-code-execution authenticated ibm guardium data-protection high-severity

← All CVEs