CVE-2026-84070
8.9IBM · Guardium Data Protection
IBM Guardium Data Protection 12.2 is vulnerable to arbitrary code execution due to improper neutralization of input during web page generation, facilitating cross-site scripting attacks.
Executive summary
A critical vulnerability in IBM Guardium Data Protection 12.2 allows remote authenticated attackers to execute arbitrary code, posing a significant risk to data integrity and system security.
Vulnerability
The software fails to properly neutralize input during web page generation, identified as CWE-79 (Cross-site Scripting). This vulnerability requires the attacker to be authenticated with low-level privileges to successfully trigger the malicious code execution.
Business impact
The ability to execute arbitrary code within a security platform like Guardium Data Protection represents a severe threat to enterprise data security. Given the high CVSS score of 8.9, this vulnerability could lead to the compromise of sensitive database activity logs, unauthorized administrative actions, or the bypass of security policies, potentially resulting in widespread regulatory and operational damage.
Remediation
Immediate Action: Apply the vendor-provided fix by installing the SqlGuard 12.0p233 Fix Pack available via the IBM Fix Central portal.
Proactive Monitoring: Review web server and application access logs for suspicious input patterns or unusual script execution requests originating from authenticated user sessions.
Compensating Controls: Implement a robust Web Application Firewall (WAF) with updated rulesets designed to detect and block cross-site scripting payloads directed at the Guardium management interface.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
The severity of this flaw, combined with the criticality of the Guardium platform, necessitates immediate patching. Organizations should prioritize the deployment of the SqlGuard 12.0p233 Fix Pack to ensure the integrity of their data protection environment and prevent potential exploitation by malicious actors.
More IBM CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief high section