rootpwn

high · CVSS v3 8.1

CVE-2026-84108

IBM Guardium Data Protection 12.2 is vulnerable to remote code execution due to improper input neutralization during web page generation. At

Overview

IBM Guardium Data Protection 12.2 is vulnerable to remote code execution due to improper input neutralization during web page generation. Attackers can exploit this flaw to run arbitrary code on the affected system. The vulnerability poses a significant risk to data protection environments.

Description

IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary code due to improper neutralization of input during web page generation.

Impact

Confidentiality: attackers can read protected data. Integrity: they can modify or delete data. Availability: they can disrupt Guardium services. The vulnerability primarily impacts organizations using Guardium to protect sensitive databases.

Remediation

Apply the latest security patch released by IBM for Guardium 12.2. If patching is not immediately possible, restrict web interface access to trusted IP ranges and enforce strict input validation on the web portal. Monitor logs for anomalous web requests and consider disabling unused web features.

Risk context

Severity is high with CVSS 8.1. No EPSS data available. Defenders should treat this as a priority vulnerability and address it promptly.

Affected products

  • IBM Guardium Data Protection 12.2
  • IBM Guardium Data Protection

Scores

Severity
high
CVSS v2
7.6
CVSS v3
8.1
CVSS v4
EPSS

CVE-2026-84108 IBM Guardium Remote Code Execution Web Input Data Protection High Severity

← All CVEs