high · CVSS v3 8.1
CVE-2026-84108
IBM Guardium Data Protection 12.2 is vulnerable to remote code execution due to improper input neutralization during web page generation. At
Overview
IBM Guardium Data Protection 12.2 is vulnerable to remote code execution due to improper input neutralization during web page generation. Attackers can exploit this flaw to run arbitrary code on the affected system. The vulnerability poses a significant risk to data protection environments.
Description
IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary code due to improper neutralization of input during web page generation.
Impact
Confidentiality: attackers can read protected data. Integrity: they can modify or delete data. Availability: they can disrupt Guardium services. The vulnerability primarily impacts organizations using Guardium to protect sensitive databases.
Remediation
Apply the latest security patch released by IBM for Guardium 12.2. If patching is not immediately possible, restrict web interface access to trusted IP ranges and enforce strict input validation on the web portal. Monitor logs for anomalous web requests and consider disabling unused web features.
Risk context
Severity is high with CVSS 8.1. No EPSS data available. Defenders should treat this as a priority vulnerability and address it promptly.
Affected products
- IBM Guardium Data Protection 12.2
- IBM Guardium Data Protection
Scores
- Severity
- high
- CVSS v2
- 7.6
- CVSS v3
- 8.1
- CVSS v4
- —
- EPSS
- —