CVE-2026-84034
8.8IBM · Guardium Data Protection
IBM Guardium Data Protection 12.2 contains hardcoded credentials in the hardware_assess and obstore binaries, allowing authenticated users to extract master secrets and access internal databases.
Executive summary
A critical vulnerability in IBM Guardium Data Protection 12.2 allows authenticated attackers to recover hardcoded master secrets and gain unauthorized database access.
Vulnerability
The application utilizes hardcoded credentials within the hardware_assess and obstore binaries. This flaw allows a low-privileged authenticated user to recover product master secrets, leading to a complete compromise of sensitive system data.
Business impact
The exploitation of this vulnerability poses a significant risk to data confidentiality and integrity, as it grants unauthorized access to the underlying database. With a CVSS score of 8.8, this high-severity flaw could lead to the exposure of sensitive organizational information, resulting in regulatory non-compliance, reputational damage, and potential service disruption.
Remediation
Immediate Action: Apply the vendor-provided fix by installing Fix Pack SqlGuard_12.0p233 as detailed in the official IBM support documentation.
Proactive Monitoring: Audit database access logs for unusual queries or unauthorized administrative activities originating from low-privileged accounts.
Compensating Controls: Restrict access to the affected binaries at the operating system level for all non-administrative users until the patch can be applied.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Given the severity of this vulnerability and the potential for total database compromise, organizations must prioritize the application of the IBM security update. Administrators should verify the installation of the specified fix pack across all Guardium instances to ensure the hardcoded credentials are removed and the system is secured against unauthorized access.
More IBM CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief high section