high · CVSS v3 8.1
CVE-2026-84241
IBM Guardium Data Protection 12.2 has a flaw that allows remote attackers to bypass security restrictions. This can lead to unauthorized dat
Overview
IBM Guardium Data Protection 12.2 has a flaw that allows remote attackers to bypass security restrictions. This can lead to unauthorized data access and manipulation.
Description
IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to improper authorization.
Impact
The vulnerability compromises confidentiality by enabling attackers to read protected data. It also threatens integrity, allowing unauthorized modifications. Availability may be impacted if attackers disrupt normal operations. Administrators and data owners are directly affected.
Remediation
Apply the latest IBM Guardium patch or upgrade to a newer version that addresses the authorization issue. Verify that role-based access controls are correctly configured and that least privilege principles are enforced. Enable detailed audit logging and monitor for anomalous access patterns. If immediate patching is not possible, restrict network access to Guardium servers and enforce IP whitelisting.
Risk context
Severity is high with a CVSS v3 score of 8.1. No EPSS data is available, but the lack of a patch means the risk remains significant. Defenders should treat this as a priority to mitigate potential data breaches.
Affected products
- IBM Guardium Data Protection 12.2
- IBM Guardium Data Protection
Scores
- Severity
- high
- CVSS v2
- 7.6
- CVSS v3
- 8.1
- CVSS v4
- —
- EPSS
- —