Description
IBM Guardium Data Protection 12.0, 12.1, and 12.2 is vulnerable to a Bypass Business Logic vulnerability in the access management control panel.
Published: 2026-04-22
Score: 4.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized privileged access via business logic bypass
Action: Patch immediately
AI Analysis

Impact

The vulnerability is a Bypass Business Logic flaw in the access management control panel of IBM Guardium Data Protection. It can allow an attacker to gain elevated privileges or access sensitive data that should otherwise be restricted. This weakness corresponds to CWE-840.

Affected Systems

IBM Guardium Data Protection products, specifically versions 12.0, 12.1, and 12.2 running on Linux-based platforms, are affected.

Risk and Exploitability

The CVSS score of 4.9 indicates moderate potential impact, while the EPSS score of less than 1 % shows a low probability of exploitation in the wild. It is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is through the administrative web interface, requiring an authenticated session or an insider with limited privileges to exploit the control panel. Attackers could elevate privileges or bypass permissions, potentially leading to unauthorized access to protected data.

Generated by OpenCVE AI on April 28, 2026 at 15:12 UTC.

Remediation

Vendor Solution

IBM encourages customers to update their systems promptly.  ProductVersions FixIBM Guardium Data Protection12.0 https://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Security&product=ibm/Information+Management/InfoSphere+Guardium&release=12.0&platform=Linux&function=fixId&fixids=SqlGuard-12.0p55_Bundle&includeSupersedes=0&source=fc IBM Guardium Data Protection12.1 https://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Security&product=ibm/Information+Management/InfoSphere+Guardium&release=12.1&platform=Linux&function=fixId&fixids=SqlGuard-12.0p140_Bundle&includeSupersedes=0&source=fc IBM Guardium Data Protection12.2 https://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Security&product=ibm/Information+Management/InfoSphere+Guardium&release=12.2&platform=Linux&function=fixId&fixids=SqlGuard-12.0p210_GPU_Dec_2025_V12.2.1_FC&includeSupersedes=0&source=fc


OpenCVE Recommended Actions

  • Apply the IBM Guardium Data Protection fix bundle (e.g., SqlGuard‑12.0p55_Bundle for 12.0 and the corresponding bundles for 12.1 and 12.2) to update to a patched version.
  • Restrict access to the access management control panel by granting only the minimum required privileges and enforcing least‑privilege policies.
  • Implement multifactor authentication for all administrative accounts that access the Guardium control panel to reduce the risk of unauthorized access.

Generated by OpenCVE AI on April 28, 2026 at 15:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Apr 2026 13:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Apr 2026 00:00:00 +0000

Type Values Removed Values Added
Description IBM Guardium Data Protection 12.0, 12.1, and 12.2 is vulnerable to a Bypass Business Logic vulnerability in the access management control panel.
Title IBM Guardium Data Protection is affected by multiple vulnerabilities
First Time appeared Ibm
Ibm guardium Data Protection
Weaknesses CWE-840
CPEs cpe:2.3:a:ibm:guardium_data_protection:12.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:guardium_data_protection:12.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:guardium_data_protection:12.1.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:guardium_data_protection:12.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:guardium_data_protection:12.2.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:guardium_data_protection:12.2:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm guardium Data Protection
References
Metrics cvssV3_1

{'score': 4.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N'}


Subscriptions

Ibm Guardium Data Protection
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-04-23T12:50:23.904Z

Reserved: 2026-01-20T21:55:55.165Z

Link: CVE-2026-1274

cve-icon Vulnrichment

Updated: 2026-04-23T12:50:19.650Z

cve-icon NVD

Status : Analyzed

Published: 2026-04-23T00:16:44.583

Modified: 2026-04-27T18:23:14.067

Link: CVE-2026-1274

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-28T15:15:34Z

Weaknesses