high · CVSS v3 7.8
CVE-2026-84089
IBM Guardium Data Protection 12.2 contains a privilege management vulnerability that enables local attackers to escalate their privileges. T
Overview
IBM Guardium Data Protection 12.2 contains a privilege management vulnerability that enables local attackers to escalate their privileges. This flaw matters because unauthorized privilege escalation within a security database monitoring platform can compromise sensitive data assets. Proper administrative boundary enforcement is missing in the affected component.
Description
IBM Guardium Data Protection 12.2 could allow a local attacker to gain elevated privileges due to improper privilege management.
Impact
This vulnerability impacts the confidentiality, integrity, and availability of the underlying host system and database security controls. Local users with low-privileged access can potentially attain elevated administrative rights. Organizations relying on this platform for compliance and monitoring face risks of unauthorized system configuration changes.
Remediation
Apply the official vendor-supplied patches or security updates provided by IBM for Guardium Data Protection 12.2. Restrict local shell access and implement the principle of least privilege for all user accounts operating on the host server. Monitor system audit logs for unauthorized privilege changes or anomalous command executions.
Risk context
Rated as a high severity issue with a CVSS score of 7.8, requiring localized access to exploit. EPSS data is currently unavailable. Remediation should be prioritized during regular maintenance cycles based on local threat modeling.
Affected products
- IBM Guardium Data Protection 12.2
Scores
- Severity
- high
- CVSS v2
- 6.8
- CVSS v3
- 7.8
- CVSS v4
- —
- EPSS
- —