CVE-2026-84106

8.9

IBM · Guardium Data Protection

IBM Guardium Data Protection 12.2 contains a vulnerability allowing remote authenticated attackers to execute arbitrary code via improper input neutralization during web page generation.

Executive summary

A vulnerability in IBM Guardium Data Protection 12.2 allows authenticated remote attackers to achieve arbitrary code execution, posing a high risk to data security.

Vulnerability

This vulnerability involves improper neutralization of input during web page generation, classified as CWE-79. An authenticated attacker can leverage this flaw to execute arbitrary code, which carries significant security implications for the integrity and availability of the affected system.

Business impact

The CVSS score of 8.9 reflects a high severity rating, indicating that successful exploitation could lead to full system compromise. Since Guardium is used for data protection, unauthorized code execution could result in the exfiltration of sensitive database information or the manipulation of security policies, leading to severe regulatory and reputational consequences.

Remediation

Immediate Action: Update to the fixed version by applying the SqlGuard_12.0p233_FixPack available through the IBM Fix Central portal.

Proactive Monitoring: Review web server and application access logs for suspicious input patterns or requests originating from authenticated user accounts that deviate from established operational baselines.

Compensating Controls: Deploy or update Web Application Firewall rules to detect and block malicious payloads targeting web page generation parameters, though this should be considered a secondary measure to patching.

Exploitation status

Public Exploit Available: No.

Analyst recommendation

Given the high CVSS score and the critical nature of the Guardium platform, organizations must prioritize the application of the provided fix pack. Administrators should verify the update installation immediately to eliminate the risk of arbitrary code execution within their data protection environment.

More IBM CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources