CVE-2026-84077

8.1

IBM · Guardium Data Protection

IBM Guardium Data Protection 12.2 contains a cross-site request forgery vulnerability that allows a remote attacker to bypass security restrictions.

Executive summary

A cross-site request forgery vulnerability in IBM Guardium Data Protection 12.2 could allow an unauthenticated remote attacker to perform unauthorized actions on behalf of a victim.

Vulnerability

This vulnerability is classified as CWE-352: Cross-Site Request Forgery (CSRF). It allows an unauthenticated remote attacker to trick a logged-in user into executing unintended actions within the affected application, potentially leading to unauthorized data modification or administrative control.

Business impact

Successful exploitation of this CSRF flaw could result in significant integrity and availability impacts for sensitive database security configurations. Given the high CVSS score of 8.1, the vulnerability poses a substantial risk of unauthorized state changes within the Guardium environment, potentially exposing the organization to data tampering or service disruption.

Remediation

Immediate Action: Apply the vendor-provided fix by installing the SqlGuard 12.0p233 FixPack available through the IBM Fix Central portal.

Proactive Monitoring: Review web application access logs for unusual patterns or requests originating from unexpected sources that coincide with administrative action endpoints.

Compensating Controls: Ensure that anti-CSRF tokens are strictly enforced across the application and utilize a Web Application Firewall (WAF) to filter suspicious cross-origin requests.

Exploitation status

Public Exploit Available: No

Analyst recommendation

The security risk posed by this CSRF vulnerability in IBM Guardium Data Protection is significant due to the critical nature of the affected software. Administrators must prioritize the deployment of the identified FixPack to remediate the flaw and prevent potential unauthorized modifications to the security posture of their monitored databases.

More IBM CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources