rootpwn

high · CVSS v3 7.8

CVE-2026-84089

IBM Guardium Data Protection 12.2 contains a privilege management vulnerability that enables local attackers to escalate their privileges. T

Overview

IBM Guardium Data Protection 12.2 contains a privilege management vulnerability that enables local attackers to escalate their privileges. This flaw matters because unauthorized privilege escalation within a security database monitoring platform can compromise sensitive data assets. Proper administrative boundary enforcement is missing in the affected component.

Description

IBM Guardium Data Protection 12.2 could allow a local attacker to gain elevated privileges due to improper privilege management.

Impact

This vulnerability impacts the confidentiality, integrity, and availability of the underlying host system and database security controls. Local users with low-privileged access can potentially attain elevated administrative rights. Organizations relying on this platform for compliance and monitoring face risks of unauthorized system configuration changes.

Remediation

Apply the official vendor-supplied patches or security updates provided by IBM for Guardium Data Protection 12.2. Restrict local shell access and implement the principle of least privilege for all user accounts operating on the host server. Monitor system audit logs for unauthorized privilege changes or anomalous command executions.

Risk context

Rated as a high severity issue with a CVSS score of 7.8, requiring localized access to exploit. EPSS data is currently unavailable. Remediation should be prioritized during regular maintenance cycles based on local threat modeling.

Affected products

  • IBM Guardium Data Protection 12.2

Scores

Severity
high
CVSS v2
6.8
CVSS v3
7.8
CVSS v4
EPSS

privilege-escalation local-attack ibm guardium defensive-analysis

← All CVEs