high · CVSS v3 8.9
CVE-2026-84106
IBM Guardium Data Protection 12.2 is vulnerable to remote authenticated code execution due to improper input neutralization in web page gene
Overview
IBM Guardium Data Protection 12.2 is vulnerable to remote authenticated code execution due to improper input neutralization in web page generation. Attackers who can authenticate to the Guardium web interface can run arbitrary code on the host. This flaw can compromise the confidentiality, integrity, and availability of protected data.
Description
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.
Impact
The vulnerability allows attackers to execute code on Guardium servers, potentially exposing sensitive data, modifying database configurations, and disrupting service availability. Database administrators, security teams, and compliance officers are directly impacted as they rely on Guardium to protect critical data assets.
Remediation
Apply the latest IBM Guardium patch or upgrade to a version where the input sanitization issue is fixed. Restrict web UI access to trusted IP ranges and enforce least privilege for Guardium accounts. Enable logging and monitor for anomalous web requests, and consider disabling the vulnerable web interface if not required.
Risk context
The CVSS v3 score of 8.9 indicates a high severity flaw with significant potential impact. Defenders should treat this as a priority patching issue.
Affected products
- IBM Guardium Data Protection 12.2
Scores
- Severity
- high
- CVSS v2
- 8.7
- CVSS v3
- 8.9
- CVSS v4
- —
- EPSS
- —