CVE-2026-84075
9.9IBM · Guardium Data Protection
IBM Guardium Data Protection 12.2 is vulnerable to a security bypass due to missing authentication in the ChangeTrackerServlet, allowing unauthenticated remote access.
Executive summary
A critical vulnerability in IBM Guardium Data Protection 12.2 allows unauthenticated remote attackers to bypass security controls, posing a severe risk of unauthorized data management actions.
Vulnerability
This flaw is classified as a missing authentication for a critical function (CWE-306). The ChangeTrackerServlet fails to verify the identity of the requester, allowing an unauthenticated remote attacker to interact with the servlet and bypass established security restrictions.
Business impact
The ability for an unauthenticated attacker to bypass security restrictions on a data protection platform carries significant risk. Successful exploitation could lead to unauthorized modification of system configurations, potential data integrity loss, or administrative interference with sensitive database monitoring workflows. Given the CVSS score of 9.9, this vulnerability is considered critical and requires immediate attention to prevent unauthorized system access.
Remediation
Immediate Action: Update IBM Guardium Data Protection to version 12.0p233 via the IBM Fix Central portal as specified in the official vendor advisory.
Proactive Monitoring: Review web access logs for unusual requests directed at the ChangeTrackerServlet and monitor for anomalous administrative configuration changes within the Guardium environment.
Compensating Controls: Implement strict network access control lists to restrict traffic to the Guardium management interface to trusted IP addresses only, and utilize a Web Application Firewall to block unauthorized attempts to access sensitive servlet endpoints.
Exploitation status
Public Exploit Available: No
Analyst recommendation
The severity of this vulnerability, combined with the lack of required authentication for exploitation, necessitates an immediate patching cycle. Security teams should prioritize the deployment of the FixPack provided by IBM to eliminate the exposure of the ChangeTrackerServlet. Failure to address this flaw leaves the core data protection infrastructure vulnerable to remote manipulation.
More IBM CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief critical section