IBM Support

Security Bulletin: IBM Guardium Data Protection is affected by multiple vulnerabilities.

Security Bulletin


Summary

IBM Guardium Data Protection has addressed these vulnerabilities in an update.

Vulnerability Details

CVEID:   CVE-2026-84084
DESCRIPTION:   IBM Guardium Data Protection could allow a remote attacker to bypass security restrictions due to a cross-site request forgery (CSRF) vulnerability.
CWE:   CWE-352: Cross-Site Request Forgery (CSRF)
CVSS Source:   IBM
CVSS Base score:   8.8
CVSS Vector:   (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)

CVEID:   CVE-2026-84882
DESCRIPTION:   IBM Security Guardium Data Protection is vulnerable to path traversal in the Universal Connector Oracle Wallet upload component. An authenticated remote attacker could exploit this vulnerability to write arbitrary files to the system.
CWE:   CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSS Source:   IBM
CVSS Base score:   7.5
CVSS Vector:   (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H)

CVEID:   CVE-2026-84105
DESCRIPTION:   IBM Guardium Data Protection could allow a remote authenticated attacker to obtain sensitive information due to improper neutralization of special elements used in an SQL command.
CWE:   CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVSS Source:   IBM
CVSS Base score:   7.7
CVSS Vector:   (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N)

CVEID:   CVE-2026-84077
DESCRIPTION:   IBM Guardium Data Protection could allow a remote attacker to bypass security restrictions due to a cross-site request forgery vulnerability.
CWE:   CWE-352: Cross-Site Request Forgery (CSRF)
CVSS Source:   IBM
CVSS Base score:   8.1
CVSS Vector:   (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H)

CVEID:   CVE-2026-84440
DESCRIPTION:   IBM Security Guardium is vulnerable to command injection in the SNMP alert notification functionality. An authenticated attacker who can influence policy alert text can cause attacker-controlled data to be executed as operating system commands by the SNMP alerter service, which runs with root privileges.
CWE:   CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVSS Source:   IBM
CVSS Base score:   7.5
CVSS Vector:   (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H)

CVEID:   CVE-2026-84036
DESCRIPTION:   IBM Guardium Data Protection could allow a remote authenticated attacker to bypass security restrictions due to improper authorization.
CWE:   CWE-285: Improper Authorization
CVSS Source:   IBM
CVSS Base score:   7.4
CVSS Vector:   (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L)

CVEID:   CVE-2026-84278
DESCRIPTION:   IBM Security Guardium Data Protection is affected by a command injection vulnerability in the SUID-root ssh_config_wrapper component. An authenticated high-privileged user can inject arbitrary commands through attacker-controlled arguments, resulting in command execution with root privileges.
CWE:   CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVSS Source:   IBM
CVSS Base score:   7.2
CVSS Vector:   (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H)

CVEID:   CVE-2026-84089
DESCRIPTION:   IBM Guardium Data Protection could allow a local attacker to gain elevated privileges due to improper privilege management.
CWE:   CWE-269: Improper Privilege Management
CVSS Source:   IBM
CVSS Base score:   7.8
CVSS Vector:   (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)

CVEID:   CVE-2026-82885
DESCRIPTION:   IBM Guardium Data Protection could allow a remote authenticated attacker to gain elevated privileges due to missing authorization in the REST API.
CWE:   CWE-862: Missing Authorization
CVSS Source:   IBM
CVSS Base score:   8.8
CVSS Vector:   (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)

CVEID:   CVE-2026-84086
DESCRIPTION:   IBM Guardium Data Protection could allow a remote authenticated attacker to execute arbitrary code due to improper limitation of a pathname to a restricted directory.
CWE:   CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSS Source:   IBM
CVSS Base score:   7.2
CVSS Vector:   (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H)

CVEID:   CVE-2026-84245
DESCRIPTION:   IBM Security Guardium Data Protection is vulnerable to a local privilege escalation in the cp_wrapper component. A low-privileged local user could exploit this vulnerability to gain root privileges and access or modify sensitive system files.
CWE:   CWE-269: Improper Privilege Management
CVSS Source:   IBM
CVSS Base score:   7.8
CVSS Vector:   (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)

CVEID:   CVE-2026-84074
DESCRIPTION:   IBM Guardium Data Protection could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.
CWE:   CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSS Source:   IBM
CVSS Base score:   8.9
CVSS Vector:   (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:L)

CVEID:   CVE-2026-84244
DESCRIPTION:   IBM Security Guardium Data Protection is vulnerable to stored cross-site scripting (XSS) in the Quick Search results grid. An unauthenticated attacker who can influence monitored database traffic could execute malicious script in the browser of an authenticated Guardium user.
CWE:   CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSS Source:   IBM
CVSS Base score:   9.3
CVSS Vector:   (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N)

CVEID:   CVE-2026-82896
DESCRIPTION:   IBM Guardium Data Protection could allow a remote authenticated attacker to traverse directories on the system due to a path traversal vulnerability.
CWE:   CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSS Source:   IBM
CVSS Base score:   7.6
CVSS Vector:   (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L)

CVEID:   CVE-2026-84250
DESCRIPTION:   IBM Security Guardium Data Protection is vulnerable due to weak cryptographic protection and a hard-coded recovery key in the pkcrypto passkey component. A local attacker could exploit this vulnerability to recover the root password and gain root privileges.
CWE:   CWE-798: Use of Hard-coded Credentials
CVSS Source:   IBM
CVSS Base score:   8.4
CVSS Vector:   (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)

CVEID:   CVE-2026-84076
DESCRIPTION:   IBM Guardium Data Protection could allow a remote authenticated attacker to bypass security restrictions due to improper authorization.
CWE:   CWE-285: Improper Authorization
CVSS Source:   IBM
CVSS Base score:   7.6
CVSS Vector:   (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L)

CVEID:   CVE-2026-84106
DESCRIPTION:   IBM Guardium Data Protection could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.
CWE:   CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSS Source:   IBM
CVSS Base score:   8.9
CVSS Vector:   (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:L)

CVEID:   CVE-2026-84842
DESCRIPTION:   IBM Security Guardium Data Protection is vulnerable to path traversal and arbitrary file deletion in the Datasource REST component. An authenticated remote attacker could exploit this vulnerability to delete files and potentially cause denial of service or impact system integrity.
CWE:   CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSS Source:   IBM
CVSS Base score:   8.1
CVSS Vector:   (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H)

CVEID:   CVE-2026-84247
DESCRIPTION:   IBM Guardium Data Protection could allow a remote authenticated attacker to cause a denial of service due to a path traversal vulnerability.
CWE:   CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSS Source:   IBM
CVSS Base score:   8.1
CVSS Vector:   (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H)

CVEID:   CVE-2026-84083
DESCRIPTION:   IBM Guardium Data Protection is vulnerable to local privilege escalation via the SUID-root nmap_wrapper binary on the Collector appliance. A local attacker with low-privileged access to the Collector can exploit insufficient argument validation in the SUID binary to execute arbitrary commands as root, resulting in full compromise of the Collector appliance.
CWE:   CWE-269: Improper Privilege Management
CVSS Source:   IBM
CVSS Base score:   7.8
CVSS Vector:   (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)

CVEID:   CVE-2026-84081
DESCRIPTION:   IBM Guardium Data Protection could allow a remote attacker to bypass security restrictions due to improper certificate validation.
CWE:   CWE-295: Improper Certificate Validation
CVSS Source:   IBM
CVSS Base score:   8.1
CVSS Vector:   (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)

CVEID:   CVE-2026-84108
DESCRIPTION:   IBM Guardium Data Protection could allow a remote attacker to execute arbitrary code due to improper neutralization of input during web page generation.
CWE:   CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSS Source:   IBM
CVSS Base score:   8.1
CVSS Vector:   (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)

CVEID:   CVE-2026-84241
DESCRIPTION:   IBM Guardium Data Protection could allow a remote attacker to bypass security restrictions due to improper authorization.
CWE:   CWE-285: Improper Authorization
CVSS Source:   IBM
CVSS Base score:   8.1
CVSS Vector:   (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)

CVEID:   CVE-2026-82967
DESCRIPTION:   IBM Security Guardium is vulnerable to an authentication bypass that allows an unauthenticated remote attacker to bypass IP-based access controls and access the Guardium management interface.
CWE:   CWE-306: Missing Authentication for Critical Function
CVSS Source:   IBM
CVSS Base score:   9.8
CVSS Vector:   (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)

CVEID:   CVE-2026-84893
DESCRIPTION:   IBM Security Guardium Data Protection is vulnerable to SQL injection in the PESI service. An authenticated attacker could exploit this vulnerability to access sensitive information in the internal database.
CWE:   CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVSS Source:   IBM
CVSS Base score:   7.6
CVSS Vector:   (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L)

CVEID:   CVE-2026-84085
DESCRIPTION:   IBM Guardium Data Protection could allow a remote attacker to execute arbitrary OS commands due to improper neutralization of special elements used in an OS command.
CWE:   CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVSS Source:   IBM
CVSS Base score:   8.1
CVSS Vector:   (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)

CVEID:   CVE-2026-84884
DESCRIPTION:   IBM Security Guardium Data Protection stores internal REST service-account passwords in a reversible plaintext-equivalent format. An authenticated attacker who gains access to the stored credential could recover the password and obtain an administrative REST access token.
CWE:   CWE-256: Plaintext Storage of a Password
CVSS Source:   IBM
CVSS Base score:   7.5
CVSS Vector:   (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H)

CVEID:   CVE-2026-84070
DESCRIPTION:   IBM Guardium Data Protection could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.
CWE:   CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSS Source:   IBM
CVSS Base score:   8.9
CVSS Vector:   (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:L)

CVEID:   CVE-2026-82832
DESCRIPTION:   IBM Guardium Data Protection could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.
CWE:   CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSS Source:   IBM
CVSS Base score:   9.6
CVSS Vector:   (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N)

CVEID:   CVE-2026-82887
DESCRIPTION:   IBM Guardium Data Protection could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
CWE:   CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVSS Source:   IBM
CVSS Base score:   8.8
CVSS Vector:   (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)

CVEID:   CVE-2026-82890
DESCRIPTION:   IBM Guardium Data Protection could allow a remote authenticated attacker to execute arbitrary JavaScript code due to improper neutralization of input during web page generation.
CWE:   CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSS Source:   IBM
CVSS Base score:   5.9
CVSS Vector:   (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:N)

CVEID:   CVE-2026-82893
DESCRIPTION:   IBM Guardium Data Protection could allow a local attacker to gain elevated privileges due to improper privilege management.
CWE:   CWE-269: Improper Privilege Management
CVSS Source:   IBM
CVSS Base score:   7.8
CVSS Vector:   (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)

CVEID:   CVE-2026-82892
DESCRIPTION:   IBM Guardium Data Protection could allow a remote attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
CWE:   CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVSS Source:   IBM
CVSS Base score:   8.1
CVSS Vector:   (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)

CVEID:   CVE-2026-85542
DESCRIPTION:   IBM Security Guardium Data Protection is affected by a command injection vulnerability in the GIM bundle import functionality. An authenticated attacker can provide a crafted GIM bundle that causes attacker-controlled arguments to be passed to the tar command, resulting in arbitrary command execution with elevated privileges on the Central Manager.
CWE:   CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVSS Source:   IBM
CVSS Base score:   8.8
CVSS Vector:   (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)

CVEID:   CVE-2026-84271
DESCRIPTION:   IBM Security Guardium Data Protection is vulnerable to a signature verification bypass in the patch installer. An attacker with local access could exploit this vulnerability to execute arbitrary code with root privileges.
CWE:   CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSS Source:   IBM
CVSS Base score:   7.8
CVSS Vector:   (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)

CVEID:   CVE-2026-84275
DESCRIPTION:   IBM Security Guardium Data Protection is vulnerable to path traversal in the GIM file-upload functionality. An unauthenticated attacker could exploit this vulnerability to write arbitrary files to the Collector.
CWE:   CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSS Source:   IBM
CVSS Base score:   9.8
CVSS Vector:   (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)

CVEID:   CVE-2026-84239
DESCRIPTION:   IBM Guardium Data Protection could allow a remote authenticated attacker to obtain sensitive information due to improper neutralization of special elements used in an SQL command.
CWE:   CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVSS Source:   IBM
CVSS Base score:   7.6
CVSS Vector:   (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L)

Affected Products and Versions

Affected Product(s)Version(s)
IBM Guardium Data Protection12.2

Workarounds and Mitigations

None

Get Notified about Future Security Bulletins

References

Off

Acknowledgement

Change History

17 Sep 2026: Initial Publication

*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.

Disclaimer

According to the Forum of Incident Response and Security Teams (FIRST), the Common Vulnerability Scoring System (CVSS) is an "industry open standard designed to convey vulnerability severity and help to determine urgency and priority of response." IBM PROVIDES THE CVSS SCORES ""AS IS"" WITHOUT WARRANTY OF ANY KIND, INCLUDING THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. CUSTOMERS ARE RESPONSIBLE FOR ASSESSING THE IMPACT OF ANY ACTUAL OR POTENTIAL SECURITY VULNERABILITY. In addition to other efforts to address potential vulnerabilities, IBM periodically updates the record of components contained in our product offerings. As part of that effort, if IBM identifies previously unidentified packages in a product/service inventory, we address relevant vulnerabilities regardless of CVE date. Inclusion of an older CVEID does not demonstrate that the referenced product has been used by IBM since that date, nor that IBM was aware of a vulnerability as of that date. We are making clients aware of relevant vulnerabilities as we become aware of them. "Affected Products and Versions" referenced in IBM Security Bulletins are intended to be only products and versions that are supported by IBM and have not passed their end-of-support or warranty date. Thus, failure to reference unsupported or extended-support products and versions in this Security Bulletin does not constitute a determination by IBM that they are unaffected by the vulnerability. Reference to one or more unsupported versions in this Security Bulletin shall not create an obligation for IBM to provide fixes for any unsupported or extended-support products or versions.

Document Location

Worldwide

[{"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SSDKGA","label":"IBM Guardium Data Protection"},"Component":"","Platform":[{"code":"PF016","label":"Linux"}],"Version":"12.2","Edition":"","Line of Business":{"code":"LOB76","label":"Data Platform"}}]

Document Information

Modified date:
17 September 2026

Initial Publish date:
17 September 2026

UID

ibm17288035