rootpwn

high · CVSS v3 8.1

CVE-2026-84241

IBM Guardium Data Protection 12.2 has a flaw that allows remote attackers to bypass security restrictions. This can lead to unauthorized dat

Overview

IBM Guardium Data Protection 12.2 has a flaw that allows remote attackers to bypass security restrictions. This can lead to unauthorized data access and manipulation.

Description

IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to improper authorization.

Impact

The vulnerability compromises confidentiality by enabling attackers to read protected data. It also threatens integrity, allowing unauthorized modifications. Availability may be impacted if attackers disrupt normal operations. Administrators and data owners are directly affected.

Remediation

Apply the latest IBM Guardium patch or upgrade to a newer version that addresses the authorization issue. Verify that role-based access controls are correctly configured and that least privilege principles are enforced. Enable detailed audit logging and monitor for anomalous access patterns. If immediate patching is not possible, restrict network access to Guardium servers and enforce IP whitelisting.

Risk context

Severity is high with a CVSS v3 score of 8.1. No EPSS data is available, but the lack of a patch means the risk remains significant. Defenders should treat this as a priority to mitigate potential data breaches.

Affected products

  • IBM Guardium Data Protection 12.2
  • IBM Guardium Data Protection

Scores

Severity
high
CVSS v2
7.6
CVSS v3
8.1
CVSS v4
EPSS

authorization bypass IBM Guardium data-protection high-severity remote-attack

← All CVEs