Description
IBM Guardium Data Protection 12.2 could allow an administrative user to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.
Published: 2026-09-23
Score: 2.7 Low
EPSS: n/a
KEV: No
Impact: Information Disclosure
Action: Apply Patch
AI Analysis

Impact

The vulnerable IBM Guardium Data Protection 12.2 application may divulge sensitive data when a detailed technical error message is returned to a browser. This behavior, tied to CWE‑209, enables an authenticated administrative user to retrieve system‑level information that is not intended for end‑user consumption. The disclosed data could then serve as a foothold for subsequent attacks against Guardium or related infrastructure.

Affected Systems

IBM Guardium Data Protection 12.2 is affected, particularly the 12.2.0 and 12.2 releases as identified by the CPE strings. No other versions are reported.

Risk and Exploitability

The CVSS score of 2.7 reflects low severity; EPSS is not available, and the vulnerability is not listed in the KEV authenticated administrative session and the trigger of a technical error condition in the browser, limiting the attack surface to internal or privileged users. Because the impact is limited to information disclosure and no remote code execution or denial of service is reported, the overall risk to the organization remains modest, though organizations with sensitive data should not ignore early mitigation.

Generated by OpenCVE AI on September 23, 2026 at 17:40 UTC.

Remediation

Vendor Solution

IBM encourages customers to update their systems promptly.  ProductVersions FixIBM Guardium Data Protection12.2 https://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Security&product=ibm/Information+Management/InfoSphere+Guardium&release=12.2&platform=Linux&function=fixId&fixids=SqlGuard_12.0p230_GPU_Jun_2026_V12.2.3_FC&includeSupersedes=0&source=fc


OpenCVE Recommended Actions

  • Apply the IBM Guardium Data Protection 12.2.3 patch or later as provided by the IBM fix ID.
  • Disable or restrict detailed technical error messages in the Guardium UI so that browsers receive generic error responses.
  • Ensure only trusted staff possess administrative privileges and enforce least‑privilege role‑based access controls.

Generated by OpenCVE AI on September 23, 2026 at 17:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Description IBM Guardium Data Protection 12.2 could allow an administrative user to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.
Title IBM Guardium Data Protection is affected by multiple vulnerabilities.
First Time appeared Ibm
Ibm guardium Data Protection
Weaknesses CWE-209
CPEs cpe:2.3:a:ibm:guardium_data_protection:12.2.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:guardium_data_protection:12.2:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm guardium Data Protection
References
Metrics cvssV3_1

{'score': 2.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Ibm Guardium Data Protection
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-23T18:56:57.695Z

Reserved: 2026-03-26T17:57:41.357Z

Link: CVE-2026-4921

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-23T16:16:43.687

Modified: 2026-09-23T19:17:30.070

Link: CVE-2026-4921

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-23T18:30:06Z

Weaknesses
  • CWE-209

    Generation of Error Message Containing Sensitive Information