CVE-2026-82896
7.6IBM · Guardium Data Protection
A path traversal vulnerability in IBM Guardium Data Protection version 12.2 allows a remote authenticated attacker to access unauthorized directories on the system.
Executive summary
A path traversal vulnerability in IBM Guardium Data Protection 12.2 allows an authenticated attacker to potentially compromise system files or data integrity.
Vulnerability
This vulnerability is a path traversal flaw (CWE-22) that permits an authenticated remote attacker to bypass directory restrictions. By manipulating input parameters, the attacker can traverse the file system, leading to unauthorized file access or modification.
Business impact
The vulnerability carries a CVSS score of 7.6, which classifies it as a high-severity risk. Successful exploitation could lead to unauthorized access to sensitive data or integrity compromise of the underlying system, potentially resulting in significant operational disruption and data exposure within the Guardium environment.
Remediation
Immediate Action: Update IBM Guardium Data Protection to the version provided in the IBM Fix Central advisory (SqlGuard 12.0p233 FixPack).
Proactive Monitoring: Monitor system access logs for unusual directory traversal patterns, such as sequences involving dot-dot-slash characters in file path requests.
Compensating Controls: Ensure that the application is deployed behind a robust Web Application Firewall (WAF) configured to inspect and block malicious path traversal attempts.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the high CVSS score and the nature of the vulnerability, organizations should treat this as a high-priority update. Administrators must apply the recommended FixPack immediately to eliminate the path traversal vector and secure the application against potential authenticated abuse.
More IBM CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief high section