high · CVSS v3 7.2
CVE-2026-84086
IBM Guardium Data Protection 12.2 contains a path traversal vulnerability that allows remote authenticated attackers to execute arbitrary co
Overview
IBM Guardium Data Protection 12.2 contains a path traversal vulnerability that allows remote authenticated attackers to execute arbitrary code. The flaw exists due to improper restriction of pathnames to a designated directory. This matters because it could lead to unauthorized system compromise within the database security environment.
Description
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper limitation of a pathname to a restricted directory.
Impact
This vulnerability impacts the integrity and availability of the affected system, potentially leading to complete system compromise. Confidentiality is also at risk as attackers could access sensitive database monitoring and security configurations. The impact is restricted to remote authenticated users with specific permissions within the application.
Remediation
Apply the latest official security patches and updates provided by IBM for Guardium Data Protection 12.2. Restrict user privileges and enforce the principle of least privilege to minimize potential abuse of administrative functions. Monitor authentication logs and system activity for unusual path traversal patterns or unauthorized command execution.
Risk context
The vulnerability carries a CVSS v3 base score of 7.2, designating it as a high-severity issue. Although EPSS data is not currently available, remediation should be prioritized due to the potential for arbitrary code execution on a critical security platform.
Affected products
- IBM Guardium Data Protection 12.2
Scores
- Severity
- high
- CVSS v2
- 8.3
- CVSS v3
- 7.2
- CVSS v4
- —
- EPSS
- —