CVE-2026-82340
9.8IBM · Guardium Data Protection
IBM Guardium Data Protection 12.2 contains an insecure deserialization vulnerability in the CAS listener that allows unauthenticated remote code execution via crafted TCP messages.
Executive summary
A critical remote code execution vulnerability in IBM Guardium Data Protection 12.2 allows unauthenticated attackers to compromise the appliance via the Change Audit System listener.
Vulnerability
This vulnerability involves insecure deserialization and reflective method dispatch within the Change Audit System (CAS) listener on TCP port 16017. An unauthenticated network attacker can leverage this flaw to trigger arbitrary code execution on the target appliance.
Business impact
The potential for unauthenticated remote code execution poses a severe risk to organizational security, as it grants attackers complete control over the affected Guardium appliance. Given the critical CVSS score of 9.8, this vulnerability could lead to total data exposure, unauthorized modification of audit trails, or total system compromise. Such an event would likely result in significant reputational damage, regulatory non-compliance, and the loss of sensitive database management oversight.
Remediation
Immediate Action: Update the IBM Guardium Data Protection appliance to the version provided in the IBM Fix Central portal, specifically applying the SqlGuard_12.0p233_FixPack.
Proactive Monitoring: Monitor network traffic destined for TCP port 16017 for suspicious serialized payloads or unexpected connection attempts from unauthorized sources.
Compensating Controls: Restrict network access to the CAS listener on TCP port 16017 to only trusted management IP addresses using firewalls or access control lists until the patch is applied.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
This vulnerability represents a critical security risk due to the potential for unauthenticated remote code execution. Administrators must prioritize the application of the referenced fix pack from IBM immediately to prevent unauthorized access and potential compromise of the Guardium infrastructure. Ensure that all standard change management procedures are followed while maintaining an aggressive timeline for deployment.
More IBM CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief critical section