CVE-2026-84074

8.9

IBM · Guardium Data Protection

IBM Guardium Data Protection 12.2 contains a vulnerability involving improper input neutralization that could allow an authenticated remote attacker to execute arbitrary code.

Executive summary

A critical vulnerability in IBM Guardium Data Protection 12.2 allows authenticated remote attackers to achieve arbitrary code execution via improper input handling.

Vulnerability

The application is susceptible to improper neutralization of input during web page generation, specifically categorized as Cross-site Scripting (CWE-79), which facilitates arbitrary code execution when triggered by an authenticated user. The vulnerability requires low privileges and user interaction, as indicated by the CVSS vector.

Business impact

The vulnerability carries a CVSS score of 8.9, reflecting a high severity risk that could lead to full system compromise. If exploited, an attacker could manipulate data, gain unauthorized control over the Guardium environment, or leverage the platform to move laterally within the network. This poses a significant threat to organizational data integrity and regulatory compliance.

Remediation

Immediate Action: Apply the vendor-provided patch by installing the SqlGuard_12.0p233_FixPack available via the IBM Fix Central portal.

Proactive Monitoring: Review web access logs for anomalous input patterns or unexpected script injections targeting the Guardium web interface.

Compensating Controls: Implement a Web Application Firewall (WAF) with strict input validation rules to filter malicious payloads that attempt to exploit improper neutralization flaws.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the potential for arbitrary code execution, this vulnerability represents a significant risk to the security of the IBM Guardium deployment. Administrators should prioritize the installation of the specified Fix Pack as soon as possible to neutralize this threat, as prompt patching remains the most effective method for preventing exploitation.

More IBM CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources